Security readout for executives and security teams
Plain-English summary
CVE-2019-11847 lets an authenticated ALEOS user gain root privileges through the command shell. That means a low-privileged account on an affected device could become full administrator. The public data rates this high severity, but it is not listed in CISA KEV and the provided sources do not show active exploitation.
Executive priority
Prioritize remediation for internet-connected, field-deployed, or operationally important ALEOS devices. This is not described as wormable, but root compromise of edge equipment can create serious operational and monitoring risk.
Technical view
The CVE describes improper privilege management in ALEOS before 4.11.0, 4.9.4, and 4.4.9. CVSS 3.1 is 7.3 with local access, low complexity, low privileges, user interaction required, and high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is most likely where organizations operate ALEOS devices with vulnerable firmware and allow authenticated shell access. The affected product list in the bundle is incomplete, so confirm device models and firmware directly against Sierra Wireless guidance.
Exploitation context
The source bundle supports authenticated local privilege escalation to root. It does not support remote unauthenticated exploitation, public weaponization, or known active exploitation. KEV status is false in the supplied data.
Researcher notes
The public record is sparse. The key facts are privilege escalation, authenticated shell context, affected ALEOS versions before the listed fixed releases, and high CIA impact. Product and model scope must be verified from the Sierra Wireless bulletin or vendor support.
Mitigation direction
- Inventory ALEOS deployments and record exact firmware versions.
- Upgrade ALEOS to 4.11.0, 4.9.4, 4.4.9, or later as applicable.
- Review Sierra Wireless bulletin guidance for model-specific applicability.
- Restrict shell access to trusted administrators only.
- Audit low-privileged device accounts and remove unnecessary access.
Validation and detection
- Compare each ALEOS firmware version against the fixed version thresholds.
- Confirm administrative shell access is limited to approved users.
- Check device account lists for stale or shared credentials.
- Review logs for unexpected privilege changes or shell activity.
- Document exceptions where vendor guidance is unavailable or ambiguous.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-11847 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H1.35.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.3HighVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2020-004/CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
