« Volver al listado

CVE-2019-3949

Estado: ModificadaCrítica (9.8)—

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-3949",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vulnreport@tenable.com",
      "affectedData": [
        {
          "vendor": "Arlo",
          "product": "Basestation firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.12.0.1_27940 and prior"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-09T18:15:11.670",
  "references": [
    {
      "url": "https://kb.arlo.com/000062274/Security-Advisory-for-Networking-Misconfiguration-and-Insufficient-UART-Protection-Mechanisms",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vulnreport@tenable.com"
    },
    {
      "url": "https://kb.arlo.com/000062274/Security-Advisory-for-Networking-Misconfiguration-and-Insufficient-UART-Protection-Mechanisms",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-16"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device."
    },
    {
      "lang": "es",
      "value": "Arlo Basestation firmware versión 1.12.0.1_27940 y anterior, contienen una configuración inapropiada de la red que permite el acceso a las interfaces de red restringidas. Esto podría permitir a un atacante cargar o descargar archivos arbitrarios y posiblemente ejecutar código malicioso en el dispositivo."
    }
  ],
  "lastModified": "2026-06-17T02:35:56.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arlo:vmb3010_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64A7DF98-4FD5-4A09-AEF1-E4D9F7D48B7D",
              "versionEndExcluding": "1.12.2.3_2762"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arlo:vmb3010:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E3750739-BEBE-40A8-8BA5-D3CB79064263"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arlo:vmb4000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D74D819-C51C-4AF0-A644-36F831B75AD6",
              "versionEndExcluding": "1.12.2.3_2762"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arlo:vmb4000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "49AB1BD0-56AE-41C6-BCC6-5CFECC0F313C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arlo:vmb3500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00403FFE-61F7-4F5A-8389-8C44E1B353C9",
              "versionEndExcluding": "1.12.2.4_2773"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arlo:vmb3500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C8C9EC35-3512-4E82-B3C2-34EE7CC77EB4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arlo:vmb4500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CBA42FC-FC70-41FD-9EFF-8320F59B0BE7",
              "versionEndExcluding": "1.12.2.4_2773"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arlo:vmb4500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0BB085BD-CDC9-41A1-B82D-A57965BC7C2C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arlo:vmb5000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADC590BD-092E-475C-B64D-68BE7F9E1312",
              "versionEndExcluding": "1.12.2.2_2824"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arlo:vmb5000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A648C2AB-F4E1-46B9-9F05-626BC739E508"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vulnreport@tenable.com"
}