9.8

CVE-2019-3949

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arlo ≫ Vmb3010 Firmware Version < 1.12.2.3_2762
   Arlo ≫ Vmb3010 Version -
Arlo ≫ Vmb4000 Firmware Version < 1.12.2.3_2762
   Arlo ≫ Vmb4000 Version -
Arlo ≫ Vmb3500 Firmware Version < 1.12.2.4_2773
   Arlo ≫ Vmb3500 Version -
Arlo ≫ Vmb4500 Firmware Version < 1.12.2.4_2773
   Arlo ≫ Vmb4500 Version -
Arlo ≫ Vmb5000 Firmware Version < 1.12.2.2_2824
   Arlo ≫ Vmb5000 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.639
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://kb.arlo.com/000062274/Security-Advisory-for-Networking-Misconfiguration-and-Insufficient-UART-Protection-Mechanisms
Vendor Advisory