CVE-2023-40458: Sierra Wireless ALEOS

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Sierra Wireless, Inc ALEOS could potentially allow a remote attacker to trigger a Denial of Service (DoS) condition for ACEManager without impairing other router functions. This condition is cleared by restarting the device.

Affected products

  • Sierra Wireless ALEOS: up to and including 4.9.8; from 4.10.0, up to and including 4.16.2

Published 2023-11-29. Last modified 2026-06-17.