ID

VAR-201904-0313


CVE

CVE-2019-3914


TITLE

Verizon Fios Quantum Gateway Firmware command injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-003348

DESCRIPTION

Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname. Verizon Fios Quantum Gateway (G1100) The firmware contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Verizon Wireless FiosQuantumGateway (G1100) is a wireless router from Verizon Wireless. A command injection vulnerability exists in VerizonFiosQuantumGateway (G1100) using firmware version 02.01.00.05. The vulnerability stems from the fact that external input data constructs executable commands, and the network system or product does not properly filter the special elements. An attacker could exploit the vulnerability to execute an illegal command

Trust: 2.25

sources: NVD: CVE-2019-3914 // JVNDB: JVNDB-2019-003348 // CNVD: CNVD-2019-24766 // VULHUB: VHN-155349

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-24766

AFFECTED PRODUCTS

vendor:verizonmodel:fios quantum gateway g1100scope:eqversion:02.01.00.05

Trust: 1.8

vendor:verizonmodel:wireless fios quantum gatewayscope:eqversion:02.01.00.05

Trust: 0.6

sources: CNVD: CNVD-2019-24766 // JVNDB: JVNDB-2019-003348 // NVD: CVE-2019-3914

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-3914
value: HIGH

Trust: 1.0

NVD: CVE-2019-3914
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-24766
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201904-579
value: HIGH

Trust: 0.6

VULHUB: VHN-155349
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-3914
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-24766
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-155349
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-3914
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2019-24766 // VULHUB: VHN-155349 // JVNDB: JVNDB-2019-003348 // CNNVD: CNNVD-201904-579 // NVD: CVE-2019-3914

PROBLEMTYPE DATA

problemtype:CWE-78

Trust: 1.1

problemtype:CWE-77

Trust: 0.9

sources: VULHUB: VHN-155349 // JVNDB: JVNDB-2019-003348 // NVD: CVE-2019-3914

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-579

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-201904-579

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-003348

PATCH

title:Fios Quantum Gatewayurl:https://www.verizon.com/home/accessories/fios-quantum-gateway/

Trust: 0.8

title:Patch for VerizonWirelessFiosQuantumGateway (G1100) command execution vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/171865

Trust: 0.6

title:Verizon Wireless Fios Quantum Gateway ( G1100 ) Repair measures for command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91391

Trust: 0.6

sources: CNVD: CNVD-2019-24766 // JVNDB: JVNDB-2019-003348 // CNNVD: CNNVD-201904-579

EXTERNAL IDS

db:NVDid:CVE-2019-3914

Trust: 3.1

db:TENABLEid:TRA-2019-17

Trust: 2.5

db:JVNDBid:JVNDB-2019-003348

Trust: 0.8

db:CNVDid:CNVD-2019-24766

Trust: 0.6

db:CNNVDid:CNNVD-201904-579

Trust: 0.6

db:VULHUBid:VHN-155349

Trust: 0.1

sources: CNVD: CNVD-2019-24766 // VULHUB: VHN-155349 // JVNDB: JVNDB-2019-003348 // CNNVD: CNNVD-201904-579 // NVD: CVE-2019-3914

REFERENCES

url:https://www.tenable.com/security/research/tra-2019-17

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2019-3914

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-3914

Trust: 0.8

sources: CNVD: CNVD-2019-24766 // VULHUB: VHN-155349 // JVNDB: JVNDB-2019-003348 // CNNVD: CNNVD-201904-579 // NVD: CVE-2019-3914

SOURCES

db:CNVDid:CNVD-2019-24766
db:VULHUBid:VHN-155349
db:JVNDBid:JVNDB-2019-003348
db:CNNVDid:CNNVD-201904-579
db:NVDid:CVE-2019-3914

LAST UPDATE DATE

2024-11-23T22:33:57.075000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-24766date:2019-07-29T00:00:00
db:VULHUBid:VHN-155349date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-003348date:2019-05-15T00:00:00
db:CNNVDid:CNNVD-201904-579date:2020-10-28T00:00:00
db:NVDid:CVE-2019-3914date:2024-11-21T04:42:51.260

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-24766date:2019-07-26T00:00:00
db:VULHUBid:VHN-155349date:2019-04-11T00:00:00
db:JVNDBid:JVNDB-2019-003348date:2019-05-15T00:00:00
db:CNNVDid:CNNVD-201904-579date:2019-04-11T00:00:00
db:NVDid:CVE-2019-3914date:2019-04-11T14:29:00.233