← Back to home
ICSA-17-115-02  ·  Published 2017-04-25  ·  View on CISA ICS-CERT ↗

Sierra Wireless AirLink Raven XE and XT

CVSS 10.0 CRITICAL

Risk Summary

ATTENTION: Remotely exploitable/low skill level to exploit. Public exploits are available.

Remediations

  • Sierra Wireless has released new firmware versions to address the forced browsing and cross-site request forgery vulnerabilities. Sierra Wireless reports that the insufficiently protected credentials vulnerability will not be addressed.
  • Sierra Wireless's Raven XE firmware Version 4.0.14
  • Sierra Wireless's Raven XT firmware Version 4.0.11
  • Sierra Wireless has released a Technical Bulletin
  • For additional information about these vulnerabilities or the recommendations provided, please contact Sierra Wireless' security team at [email protected]

Affected Vendors

Sierra Wireless

Affected Products (2)

Sierra Wireless · AirLink Raven XT < 4.0.11
Sierra Wireless · AirLink Raven XE < 4.0.14

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more