Canadian Centre for Cyber Security · English · AV18-006SierraWireless ALEOS update 4.4.5 for AirLink devices701, CVE-2017-3731, CVE-2016-2181, CVE-2016-0702, CVE-2017-3732, CVE-2016-2182, CVE-2016-0705, CVE-2016-2105, CVE-2016-2183, CVE-2016-0797, CVE-2016-2106, CVE-2016-6302, CVE-2016-0798, CVE-2016-2107, CVE-2016-6303, CVE-2016-0799, CVE-2016-2109, CVE-2016-6304, CVE-2016-0800, CVE-2016-2176, CVE-2016-6306, CVE-2016-2842, CVE-2016-2177, CVE-2015-3195, CVE-2015-1794, CVE-2016-2178, CVE-2015-3197, CVE-2015-3193, CVE-2016-2179, CVE-2015-3194, CVE-2016-2180
Dropbear: CVE-2017-9078 and CVE-2017-9079
Tcpdump and Libpcap: CVE-2014-8769 and CVE-2014-8767
Linux kernel: CVE-2017-14106, CVE-2014-7822, CVE-2014-9888, CVE-2015-3288
OpenVPN: CVE-2017-7520 and CVE-2017-7479
SNMP: CVE-2015-5621
Libcurl: CVE-2016-5421
Dnsmasq: CVE-2017-14496, CVE-2017-14491, CVE-2017-14492, CVE-2017-14493, CVE-2017-14494, CVE-2017-14495
Suggested Action
CCIRC recommends that system administrators test and deploy the vendor released updates on affected platforms accordingly.
CCIRC recommends confirming if your remote access, mobile or off-site solutions include this type of cellular gateway. Contact your integrator or service provider for more information on how to properly test and deploy the vendor released updates on affected platforms accordingly.
References:
Release Notes:
https://source.sierrawireless.com/resources/airlink/s
Official advisory ↗