WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Sierra Wireless AirLink ALEOS (Update B) (ICSA-19-122-03) – Products Used in the Water and Wastewater and Energy Sectors
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Sierra Wireless AirLink ALEOS (Update B) (ICSA-19-122-03) – Products Used in the Water and Wastewater and Energy Sectors

Author: Charles Egli

Created: Thursday, April 23, 2020 - 18:08

Categories: Cybersecurity

April 23, 2020

CISA has updated this advisory with additional details on the affected products and mitigation measures. Read the advisory at CISA.

August 20, 2019

The NCCIC has updated this advisory with additionally information on mitigating measures. Read the advisory at CISA.

May 2, 2019

The NCCIC has published an advisory on OS command injection, use of hard-coded credentials, unrestricted upload of file with dangerous type, cross-site scripting, cross-site request forgery, information exposure, and missing encryption of sensitive data vulnerabilities in Sierra Wireless AirLink ALEOS. Numerous products and versions of these products are affected. Successful exploitation of these vulnerabilities could allow attackers to remotely execute code, discover user credentials, upload files, or discover file paths. Sierra Wireless recommends users upgrade to the latest version of ALEOS. The NCCIC also provides a series of recommendations for addressing the vulnerabilities. Read the advisory at NCCIC/ICS-CERT.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 11, 2026

Jun 11, 2026 in Cybersecurity
Members Only

(TLP:GREEN) FBI Report – Elevated Cyber Risk to Utility Providers Supporting FIFA World Cup 2026 Tournament Events

Jun 11, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar