CVE-2023-40464: Sierra Wireless ALEOS

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

Affected products

Published 2023-12-04. Last modified 2026-06-17.