CVE-2023-40460 Information
Dec 08, 2023
cve
Description
The ACEManager component of ALEOS 4.16 and earlier does not
validate uploaded file names and types which could potentially allow
an authenticated user to perform client-side script execution within
ACEManager altering the device functionality until the device is
restarted.