CVE-2023-40464: Sierra Wireless ALEOS
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.
Affected products
- Sierra Wireless ALEOS: up to and including 4.16.0
Published 2023-12-04. Last modified 2026-06-17.