First published: Tue Dec 31 2019(Updated: )
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Blink Xt2 Sync Module Firmware | <2.3.11 | |
Amazon Blink Xt2 Sync Module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-3984.
The severity of CVE-2019-3984 is critical, with a CVSS score of 9.8.
Blink XT2 Sync Module firmware prior to 2.13.11 is affected by CVE-2019-3984.
Remote attackers can exploit CVE-2019-3984 by executing arbitrary commands on the device due to improperly sanitized input when the device retrieves update scripts from the internet.
No, Amazon Blink Xt2 Sync Module is not vulnerable to CVE-2019-3984.