HIGH

CVE-2019-19494

CVSS v3

8.8

HIGH

EPSS Score

69.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.

Technical details

Published
1/9/2020

Frequently asked questions

What is CVE-2019-19494?

Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker to execute arbitrary code at the kernel level via JavaScript run in a victim's browser. Examples of affected products include Sagemcom F@st 3890 prior to 50.10.21_T4, Sagemcom F@st 3890 prior to 05.76.6.3f, Sagemcom F@st 3686 3.428.0, Sagemcom F@st 3686 4.83.0, NETGEAR CG3700EMR 2.01.05, NETGEAR CG3700EMR 2.01.03, NETGEAR C6250EMR 2.01.05, NETGEAR C6250EMR 2.01.03, Technicolor TC7230 STEB 01.25, COMPAL 7284E 5.510.5.11, and COMPAL 7486E 5.510.5.11.

Is CVE-2019-19494 actively exploited?

Active exploitation of CVE-2019-19494 has not been confirmed. The EPSS score is 69.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-19494?

CVE-2019-19494 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-19494 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.