First published: Tue Jul 09 2019(Updated: )
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arlo Vmb3010 Firmware | <1.12.2.3_2762 | |
Arlo Vmb3010 Firmware | ||
Arlo Vmb4000 Firmware | <1.12.2.3_2762 | |
Arlo VMB4000 | ||
Arlo Vmb3500 | <1.12.2.4_2773 | |
Arlo Vmb3500 Firmware | ||
Arlo VMB4500 | <1.12.2.4_2773 | |
Arlo Vmb4500 Firmware | ||
Arlo Vmb5000 Firmware | <1.12.2.2_2824 | |
Arlo VMB5000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3949 is classified as a high severity vulnerability due to its potential to allow unauthorized access to restricted network interfaces.
To fix CVE-2019-3949, update the Arlo basestation firmware to version 1.12.2.2_2824 or higher.
CVE-2019-3949 affects several Arlo basestation firmware versions, specifically versions prior to 1.12.2.2.
The risks of CVE-2019-3949 include the potential for attackers to upload or download arbitrary files and execute malicious code on the affected devices.
Currently, the recommended action for CVE-2019-3949 is to update the firmware as there are no known workarounds.