Crestron kayıtları
crestron üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,5
- Silahlaştırılmış
- 2 · %5
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 1081 gün
Tekrar eden sınıflar
- CWE-284 Improper Access Control7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-287 Improper Authentication2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-255 Credentials Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-3929Silahlaştırılmış | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Kritik9,8 | KEV | %99,0 | 30 Nis 2019 |
62Bu hafta | CVE-2022-23178Kavram kanıtı | An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices.crestron · hd-md4x2-4k-e firmware · CWE-287 | Kritik9,8 | — | %75,2 | 15 Oca 2022 |
50Planlayın | CVE-2017-16709Silahlaştırılmış | Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated adminicrestron · airmedia am-100 firmware | Yüksek7,2 | — | %72,0 | 11 Tem 2018 |
50Planlayın | CVE-2019-3932İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password crestron · am-100 firmware · CWE-249 | Kritik9,8 | — | %36,3 | 30 Nis 2019 |
44Planlayın | CVE-2016-5640Kavram kanıtı | Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attacrestron · airmedia am-100 firmware · CWE-77 | Kritik9,8 | — | %17,7 | 2 Ağu 2016 |
42Planlayın | CVE-2018-10630İstismar yok | For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication dicrestron · tsw-x60 firmware · CWE-284 | Kritik9,8 | — | %10,9 | 10 Ağu 2018 |
41Planlayın | CVE-2019-18184İstismar yok | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.crestron · dmc-stro firmware · CWE-78 | Kritik9,8 | — | %8,1 | 27 Kas 2019 |
41Planlayın | CVE-2018-11228İstismar yok | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote codecrestron · crestron toolbox protocol firmware · CWE-94 | Kritik9,8 | — | %7,5 | 7 Haz 2018 |
41Planlayın | CVE-2019-3930İstismar yok | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-121 | Kritik9,8 | — | %7,0 | 30 Nis 2019 |
41Planlayın | CVE-2019-3926İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1crestron · am-100 firmware · CWE-79 | Kritik9,8 | — | %6,9 | 30 Nis 2019 |
41Planlayın | CVE-2019-3925İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1crestron · am-100 firmware · CWE-79 | Kritik9,8 | — | %6,9 | 30 Nis 2019 |
41Planlayın | CVE-2018-11229İstismar yok | Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote codecrestron · crestron toolbox protocol firmware · CWE-78 | Kritik9,8 | — | %5,6 | 7 Haz 2018 |
40Planlayın | CVE-2016-5668İstismar yok | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change secrestron · dm-txrx-100-str firmware | Kritik9,8 | — | %4,4 | 2 Ağu 2016 |
40Planlayın | CVE-2016-5667İstismar yok | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct crestron · dm-txrx-100-str firmware | Kritik9,8 | — | %4,4 | 2 Ağu 2016 |
40Planlayın | CVE-2016-5666İstismar yok | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows recrestron · dm-txrx-100-str firmware | Kritik9,8 | — | %4,2 | 2 Ağu 2016 |
40Planlayın | CVE-2016-5670İstismar yok | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, whicrestron · dm-txrx-100-str firmware · CWE-255 | Kritik9,8 | — | %3,2 | 2 Ağu 2016 |
40Planlayın | CVE-2019-3939İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the wcrestron · am-100 firmware · CWE-16 | Kritik9,8 | — | %2,8 | 30 Nis 2019 |
40Planlayın | CVE-2018-5553İstismar yok | Crestron DGE-100 Console Command Injection (FIXED)crestron · dge-100 firmware · CWE-78 | Kritik9,8 | — | %2,5 | 10 Tem 2018 |
40Planlayın | CVE-2019-3927İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the icrestron · am-100 firmware · CWE-284 | Kritik9,8 | — | %2,2 | 30 Nis 2019 |
39İzleyin | CVE-2019-3910İstismar yok | Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script.crestron · airmedia am-100 firmware | Kritik9,1 | — | %8,6 | 18 Oca 2019 |
39İzleyin | CVE-2016-5669İstismar yok | Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an crestron · dm-txrx-100-str firmware | Kritik9,8 | — | %1,6 | 2 Ağu 2016 |
37İzleyin | CVE-2019-3931İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via craftecrestron · am-100 firmware · CWE-88 | Yüksek8,8 | — | %5,8 | 30 Nis 2019 |
37İzleyin | CVE-2019-3935İstismar yok | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP crestron · am-100 firmware · CWE-284 | Kritik9,1 | — | %3,3 | 30 Nis 2019 |
36İzleyin | CVE-2016-5639Kavram kanıtı | Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attaccrestron · airmedia am-100 firmware · CWE-22 | Yüksek7,5 | — | %20,8 | 2 Ağu 2016 |
36İzleyin | CVE-2018-13341Kavram kanıtı | Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts mcrestron · tsw-x60 firmware | Yüksek8,8 | — | %3,7 | 10 Ağu 2018 |
- CVE-2019-392999Hemen
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99crestron · am-100 firmware30 Nis 2019
- CVE-2022-2317862Bu hafta
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices.
KritikCVSS 9,8Kavram kanıtıEPSS %75crestron · hd-md4x2-4k-e firmware15 Oca 2022
- CVE-2017-1670950Planlayın
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated admini
YüksekCVSS 7,2SilahlaştırılmışEPSS %72crestron · airmedia am-100 firmware11 Tem 2018
- CVE-2019-393250Planlayın
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password
KritikCVSS 9,8İstismar yokEPSS %36crestron · am-100 firmware30 Nis 2019
- CVE-2016-564044Planlayın
Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote atta
KritikCVSS 9,8Kavram kanıtıEPSS %18crestron · airmedia am-100 firmware2 Ağu 2016
- CVE-2018-1063042Planlayın
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication di
KritikCVSS 9,8İstismar yokEPSS %11crestron · tsw-x60 firmware10 Ağu 2018
- CVE-2019-1818441Planlayın
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
KritikCVSS 9,8İstismar yokEPSS %8crestron · dmc-stro firmware27 Kas 2019
- CVE-2018-1122841Planlayın
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code
KritikCVSS 9,8İstismar yokEPSS %7crestron · crestron toolbox protocol firmware7 Haz 2018
- CVE-2019-393041Planlayın
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
KritikCVSS 9,8İstismar yokEPSS %7crestron · am-100 firmware30 Nis 2019
- CVE-2019-392641Planlayın
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1
KritikCVSS 9,8İstismar yokEPSS %7crestron · am-100 firmware30 Nis 2019
- CVE-2019-392541Planlayın
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.1
KritikCVSS 9,8İstismar yokEPSS %7crestron · am-100 firmware30 Nis 2019
- CVE-2018-1122941Planlayın
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code
KritikCVSS 9,8İstismar yokEPSS %6crestron · crestron toolbox protocol firmware7 Haz 2018
- CVE-2016-566840Planlayın
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change se
KritikCVSS 9,8İstismar yokEPSS %4crestron · dm-txrx-100-str firmware2 Ağu 2016
- CVE-2016-566740Planlayın
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct
KritikCVSS 9,8İstismar yokEPSS %4crestron · dm-txrx-100-str firmware2 Ağu 2016
- CVE-2016-566640Planlayın
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows re
KritikCVSS 9,8İstismar yokEPSS %4crestron · dm-txrx-100-str firmware2 Ağu 2016
- CVE-2016-567040Planlayın
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, whi
KritikCVSS 9,8İstismar yokEPSS %3crestron · dm-txrx-100-str firmware2 Ağu 2016
- CVE-2019-393940Planlayın
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the w
KritikCVSS 9,8İstismar yokEPSS %3crestron · am-100 firmware30 Nis 2019
- CVE-2018-555340Planlayın
Crestron DGE-100 Console Command Injection (FIXED)
KritikCVSS 9,8İstismar yokEPSS %2crestron · dge-100 firmware10 Tem 2018
- CVE-2019-392740Planlayın
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the i
KritikCVSS 9,8İstismar yokEPSS %2crestron · am-100 firmware30 Nis 2019
- CVE-2019-391039İzleyin
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script.
KritikCVSS 9,1İstismar yokEPSS %9crestron · airmedia am-100 firmware18 Oca 2019
- CVE-2016-566939İzleyin
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an
KritikCVSS 9,8İstismar yokEPSS %2crestron · dm-txrx-100-str firmware2 Ağu 2016
- CVE-2019-393137İzleyin
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafte
YüksekCVSS 8,8İstismar yokEPSS %6crestron · am-100 firmware30 Nis 2019
- CVE-2019-393537İzleyin
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP
KritikCVSS 9,1İstismar yokEPSS %3crestron · am-100 firmware30 Nis 2019
- CVE-2016-563936İzleyin
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attac
YüksekCVSS 7,5Kavram kanıtıEPSS %21crestron · airmedia am-100 firmware2 Ağu 2016
- CVE-2018-1334136İzleyin
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts m
YüksekCVSS 8,8Kavram kanıtıEPSS %4crestron · tsw-x60 firmware10 Ağu 2018