Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-19494


Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.


Published

2020-01-09T13:15:10.993

Last Modified

2024-11-21T04:34:50.037

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sagemcom f\@st_3890_firmware < 50.10.21_t4 Yes
Hardware sagemcom f\@st_3890 - No
Operating System sagemcom f\@st_3890_firmware < 05.76.6.3f Yes
Hardware sagemcom f\@st_3890 - No
Operating System sagemcom f\@st_3686_firmware 3.428.0 Yes
Operating System sagemcom f\@st_3686_firmware 4.83.0 Yes
Hardware sagemcom f\@st_3686 - No
Operating System netgear cg3700emr_firmware 2.01.03 Yes
Operating System netgear cg3700emr_firmware 2.01.05 Yes
Hardware netgear cg3700emr - No
Operating System netgear c6250emr_firmware 2.01.03 Yes
Operating System netgear c6250emr_firmware 2.01.05 Yes
Hardware netgear c6250emr - No
Operating System technicolor tc7230_steb_firmware 01.25 Yes
Hardware technicolor tc7230_steb - No
Operating System compal 7284e_firmware 5.510.5.11 Yes
Hardware compal 7284e - No
Operating System compal 7486e_firmware 5.510.5.11 Yes
Hardware compal 7486e - No

References