OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T17:39:12.629Z
Reserved: 2023-07-14T00:00:00
Link: CVE-2023-38321
No data.
Status : Modified
Published: 2023-12-25T09:15:07.223
Modified: 2024-11-21T08:13:19.683
Link: CVE-2023-38321
No data.
OpenCVE Enrichment
No data.
Weaknesses