Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-6926 There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH sessi… Am 300 Firmware Mitigation only Fix from $1,9502024-01-23 HIGH 7.5 CVE-2023-38405 On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash. Cp3n 6505417 Firmware 1.8001.0187+ Fix from $1,9502023-07-17 HIGH 8.8 CVE-2022-40298 Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the Ai… Airmedia Mitigation only Fix from $1,9502022-09-23 HIGH 8.8 CVE-2022-34102 Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause th… Airmedia Mitigation only Fix from $1,9502022-09-13 HIGH 7.8 CVE-2022-34101 A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain… Airmedia Mitigation only Fix from $1,9502022-09-13 HIGH 8.8 CVE-2022-34100 A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level… Airmedia Mitigation only Fix from $1,9502022-09-13 CRITICAL 9.8 CVE-2022-23178EPSS 76% An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthen… Hd Md4x2 4k E Firmware No fix yet Fix from $2,3002022-01-15 HIGH 7.5 CVE-2020-16839 On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthentic… Dm Nvx Dir 80 Firmware Mitigation only Fix from $1,9502021-07-30 CRITICAL 9.8 CVE-2019-18184EPSS 8% Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. Dmc Stro Firmware No fix yet Fix from $2,3002019-11-27 CRITICAL 9.8 CVE-2019-3939 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interf… Am 100 Firmware Mitigation only Fix from $2,3002019-04-30 CRITICAL 9.1 CVE-2019-3935 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requ… Am 100 Firmware No fix yet Fix from $2,3002019-04-30 HIGH 7.8 CVE-2019-3937 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration optio… Am 100 Firmware No fix yet Fix from $1,9502019-04-30 HIGH 7.8 CVE-2019-3938 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file gener… Am 100 Firmware No fix yet Fix from $1,9502019-04-30 HIGH 7.5 CVE-2019-3936 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The … Am 100 Firmware Mitigation only Fix from $1,9502019-04-30 MEDIUM 5.3 CVE-2019-3934EPSS 8% Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST requ… Am 100 Firmware No fix yet Fix from $1,6002019-04-30 CRITICAL 9.8 CVE-2019-3925EPSS 7% Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.… Am 100 Firmware No fix yet Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-3926EPSS 7% Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14… Am 100 Firmware No fix yet Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-3927 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.… Am 100 Firmware No fix yet Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-3929 KEVEPSS 99% The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befo… Am 100 Firmware 2.4.1.19+ Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-3930EPSS 7% The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befo… Am 100 Firmware 2.4.1.19+ Fix from $2,3002019-04-30 CRITICAL 9.8 CVE-2019-3932EPSS 36% Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return… Am 100 Firmware No fix yet Fix from $2,3002019-04-30 HIGH 8.8 CVE-2019-3931EPSS 6% Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP re… Am 100 Firmware No fix yet Fix from $1,9502019-04-30 MEDIUM 5.3 CVE-2019-3928 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.… Am 100 Firmware Mitigation only Fix from $1,6002019-04-30 MEDIUM 5.3 CVE-2019-3933EPSS 6% Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/bro… Am 100 Firmware No fix yet Fix from $1,6002019-04-30 CRITICAL 9.1 CVE-2019-3910EPSS 9% Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote us… Airmedia Am 100 Firmware 1.6.0.2+ Fix from $2,3002019-01-18 CRITICAL 9.8 CVE-2018-10630EPSS 11% For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, a… Tsw X60 Firmware 1.502.0047.001 / 2.001.0037.001+ Fix from $2,3002018-08-10 HIGH 8.8 CVE-2018-13341 Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be cal… Tsw X60 Firmware 1.502.0047.00 / 2.001.0037.001+ Fix from $1,9502018-08-10 HIGH 7.2 CVE-2017-16709EPSS 72% Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators … Airmedia Am 100 Firmware 1.6.0 / 2.7.0+ Fix from $1,9502018-07-11 CRITICAL 9.8 CVE-2018-5553 The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.… Dge 100 Firmware after 1.3384.00049.001 Fix from $2,3002018-07-10 CRITICAL 9.8 CVE-2018-11228EPSS 7% Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code executio… Crestron Toolbox Protocol Firmware 2.001.0037.001+ Fix from $2,3002018-06-08