Vulnerability Intelligence Report
CVE-2013-2819
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action.
No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:1.87%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| sierrawireless | raven_x_ev-do_firmware | 4221_4.0.11.003, 4228_4.0.11.003 |
| sierrawireless | airlink_mp_at\&t | all |
| sierrawireless | airlink_mp_at\&t_wifi | all |
| sierrawireless | airlink_mp_bell | all |
| sierrawireless | airlink_mp_bell_wifi | all |
| sierrawireless | airlink_mp_row | all |
| sierrawireless | airlink_mp_row_wifi | all |
| sierrawireless | airlink_mp_sprint | all |
| sierrawireless | airlink_mp_sprint_wifi | all |
| sierrawireless | airlink_mp_telus | all |
| sierrawireless | airlink_mp_telus_wifi | all |
| sierrawireless | airlink_mp_verizon | all |
| sierrawireless | airlink_mp_verizon_wifi | all |
| sierrawireless | pinpoint_x | all |
| sierrawireless | pinpoint_xt | all |
| sierrawireless | raven_x | all |
| sierrawireless | raven_x_ev-do | all |
| sierrawireless | raven_xe | all |
| sierrawireless | raven_xt | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.866%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA |
| Reserved | 2013-04-11T00:00:00 |
| Published | 2014-01-15T16:00:00 |
| Patch Date | 2014-01-14 |
| Last Updated | 2024-08-06T15:52:19 |
Community Chatter & Buzz