HIGH · 8.8

CVE-2019-19494

Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's b...

Vulnerability Description

Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SagemcomF\@St 3890 Firmware< 50.10.21_t4
SagemcomF\@St 3890-
SagemcomF\@St 3686 Firmware3.428.0
SagemcomF\@St 3686-
NetgearCg3700Emr Firmware2.01.03
NetgearCg3700Emr-
NetgearC6250Emr Firmware2.01.03
NetgearC6250Emr-
TechnicolorTc7230 Steb Firmware01.25
TechnicolorTc7230 Steb-
Compal7284E Firmware5.510.5.11
Compal7284E-
Compal7486E Firmware5.510.5.11
Compal7486E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-19494?

CVE-2019-19494 is a vulnerability with a CVSS score of 8.8 (HIGH). Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's b...

How severe is CVE-2019-19494?

CVE-2019-19494 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-19494?

Check the references section above for vendor advisories and patch information. Affected products include: Sagemcom F\@St 3890 Firmware, Sagemcom F\@St 3890, Sagemcom F\@St 3686 Firmware, Sagemcom F\@St 3686, Netgear Cg3700Emr Firmware.