CVE-2023-38321 Information
Dec 27, 2023
cve
Description
OpenNDS as used in Sierra Wireless ALEOS before 4.17.0.12 and other products allows remote attackers to cause a denial of service (NULL pointer dereference daemon crash and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter and client-token.
Reference
https://openwrt.org/docs/guide-user/services/captive-portal/opennds https://github.com/openNDS/openNDS/blob/master/ChangeLog https://source.sierrawireless.com/-/media/support_downloads/security-bulletins/pdf/swi-psa-2023-006-r3.ashx
Share on: