CVE-2019-11851: Sierra Wireless ALEOS

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.

Affected products

  • Sierra Wireless ALEOS: from 4.10.0, before 4.14.0 (fixed in 4.14.0); from 4.5.0, before 4.9.5 (fixed in 4.9.5); before 4.4.9 (fixed in 4.4.9)

Published 2022-12-26. Last modified 2026-06-17.