CVE-2019-11855: Sierra Wireless ALEOS

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

Affected products

  • Sierra Wireless ALEOS: before 4.12.0 (fixed in 4.12.0); before 4.9.5 (fixed in 4.9.5); before 4.4.9 (fixed in 4.4.9)

Published 2020-08-21. Last modified 2026-06-17.