CVE-2019-11848: Sierra Wireless ALEOS
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length checking when handling certain user-provided values.
Affected products
- Sierra Wireless ALEOS: before 4.13.0 (fixed in 4.13.0); before 4.9.5 (fixed in 4.9.5); before 4.4.9 (fixed in 4.4.9)
Published 2020-08-21. Last modified 2026-06-17.