CVE-2019-3949: Critical severity arlo vmb3010 firmware vulnerability
Arlo Basestation firmware 1.12.0.127940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3949?
CVE-2019-3949 is classified as a high severity vulnerability due to its potential to allow unauthorized access to restricted network interfaces.
How do I fix CVE-2019-3949?
To fix CVE-2019-3949, update the Arlo basestation firmware to version 1.12.2.2_2824 or higher.
What devices are affected by CVE-2019-3949?
CVE-2019-3949 affects several Arlo basestation firmware versions, specifically versions prior to 1.12.2.2.
What are the risks associated with CVE-2019-3949?
The risks of CVE-2019-3949 include the potential for attackers to upload or download arbitrary files and execute malicious code on the affected devices.
Is there a workaround for CVE-2019-3949?
Currently, the recommended action for CVE-2019-3949 is to update the firmware as there are no known workarounds.