10

CVE-2019-3950

Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.

Data is provided by the National Vulnerability Database (NVD)
ArloVmb3010 Firmware Version < 1.12.2.3_2762
   ArloVmb3010 Version-
ArloVmb4000 Firmware Version < 1.12.2.3_2762
   ArloVmb4000 Version-
ArloVmb3500 Firmware Version < 1.12.2.4_2773
   ArloVmb3500 Version-
ArloVmb4500 Firmware Version < 1.12.2.4_2773
   ArloVmb4500 Version-
ArloVmb5000 Firmware Version < 1.12.2.2_2824
   ArloVmb5000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.47% 0.617
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.