The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authenticated user to perform client-side script execution within ACEManager, altering the device functionality until the device is restarted.
This Cyber News was published on www.tenable.com. Publication date: Thu, 07 Dec 2023 13:23:20 +0000