Vulnerability Description
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain access via a dictionary attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgear | Arlo Base Station Firmware | <= 1.7.5_6178 |
| Netgear | Vmb30X0 | - |
| Netgear | Vmk3Xx0 | - |
| Netgear | Vms3Xx0 | - |
| Netgear | Arlo Q Camera Firmware | <= 1.8.0_5551 |
| Netgear | Vmc3040 | - |
| Netgear | Arlo Q Plus Camera Firmware | <= 1.8.1_6094 |
| Netgear | Vmc3040S | - |
Related Weaknesses (CWE)
References
- http://blog.newskysecurity.com/2016/09/brute-force-vulnerability-netgear-arlo/Third Party Advisory
- http://kb.netgear.com/30731/Arlo-WiFi-Default-Password-Security-VulnerabilityMitigationVendor Advisory
- http://www.securityfocus.com/bid/95266Third Party AdvisoryVDB Entry
- http://blog.newskysecurity.com/2016/09/brute-force-vulnerability-netgear-arlo/Third Party Advisory
- http://kb.netgear.com/30731/Arlo-WiFi-Default-Password-Security-VulnerabilityMitigationVendor Advisory
- http://www.securityfocus.com/bid/95266Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-10116?
CVE-2016-10116 is a vulnerability with a CVSS score of 8.1 (HIGH). NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adje...
How severe is CVE-2016-10116?
CVE-2016-10116 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10116?
Check the references section above for vendor advisories and patch information. Affected products include: Netgear Arlo Base Station Firmware, Netgear Vmb30X0, Netgear Vmk3Xx0, Netgear Vms3Xx0, Netgear Arlo Q Camera Firmware.