CVE-2019-3949
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.2.3_2762 |
| Running on/with | Platform Versions |
|---|---|
Arlo Vmb3010 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.2.3_2762 |
| Running on/with | Platform Versions |
|---|---|
Arlo Vmb4000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.2.4_2773 |
| Running on/with | Platform Versions |
|---|---|
Arlo Vmb3500 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.2.4_2773 |
| Running on/with | Platform Versions |
|---|---|
Arlo Vmb4500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.12.2.2_2824 |
| Running on/with | Platform Versions |
|---|---|
Arlo Vmb5000 | All versions |
Related CWEs
References (2)
Source: vulnreport@tenable.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.