CRITICAL · 9.8

CVE-2019-3949

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or downloa...

Vulnerability Description

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ArloVmb3010 Firmware< 1.12.2.3_2762
ArloVmb3010-
ArloVmb4000 Firmware< 1.12.2.3_2762
ArloVmb4000-
ArloVmb3500 Firmware< 1.12.2.4_2773
ArloVmb3500-
ArloVmb4500 Firmware< 1.12.2.4_2773
ArloVmb4500-
ArloVmb5000 Firmware< 1.12.2.2_2824
ArloVmb5000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-3949?

CVE-2019-3949 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or downloa...

How severe is CVE-2019-3949?

CVE-2019-3949 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-3949?

Check the references section above for vendor advisories and patch information. Affected products include: Arlo Vmb3010 Firmware, Arlo Vmb3010, Arlo Vmb4000 Firmware, Arlo Vmb4000, Arlo Vmb3500 Firmware.