CVE-2019-3949
 
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
Arlo Basestation firmware versión 1.12.0.1_27940 y anterior, contienen una configuración inapropiada de la red que permite el acceso a las interfaces de red restringidas. Esto podría permitir a un atacante cargar o descargar archivos arbitrarios y posiblemente ejecutar código malicioso en el dispositivo.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-01-03 CVE Reserved
- 2019-07-09 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-16: Configuration
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arlo Search vendor "Arlo" | Vmb3010 Firmware Search vendor "Arlo" for product "Vmb3010 Firmware" | < 1.12.2.3_2762 Search vendor "Arlo" for product "Vmb3010 Firmware" and version " < 1.12.2.3_2762" | - |
Affected
| in | Arlo Search vendor "Arlo" | Vmb3010 Search vendor "Arlo" for product "Vmb3010" | - | - |
Safe
|
Arlo Search vendor "Arlo" | Vmb4000 Firmware Search vendor "Arlo" for product "Vmb4000 Firmware" | < 1.12.2.3_2762 Search vendor "Arlo" for product "Vmb4000 Firmware" and version " < 1.12.2.3_2762" | - |
Affected
| in | Arlo Search vendor "Arlo" | Vmb4000 Search vendor "Arlo" for product "Vmb4000" | - | - |
Safe
|
Arlo Search vendor "Arlo" | Vmb3500 Firmware Search vendor "Arlo" for product "Vmb3500 Firmware" | < 1.12.2.4_2773 Search vendor "Arlo" for product "Vmb3500 Firmware" and version " < 1.12.2.4_2773" | - |
Affected
| in | Arlo Search vendor "Arlo" | Vmb3500 Search vendor "Arlo" for product "Vmb3500" | - | - |
Safe
|
Arlo Search vendor "Arlo" | Vmb4500 Firmware Search vendor "Arlo" for product "Vmb4500 Firmware" | < 1.12.2.4_2773 Search vendor "Arlo" for product "Vmb4500 Firmware" and version " < 1.12.2.4_2773" | - |
Affected
| in | Arlo Search vendor "Arlo" | Vmb4500 Search vendor "Arlo" for product "Vmb4500" | - | - |
Safe
|
Arlo Search vendor "Arlo" | Vmb5000 Firmware Search vendor "Arlo" for product "Vmb5000 Firmware" | < 1.12.2.2_2824 Search vendor "Arlo" for product "Vmb5000 Firmware" and version " < 1.12.2.2_2824" | - |
Affected
| in | Arlo Search vendor "Arlo" | Vmb5000 Search vendor "Arlo" for product "Vmb5000" | - | - |
Safe
|