Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Am 300 Firmware HIGH 7.8
CVE-2023-6926

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH sessi…

Mitigation only
Fix from $1,950 2024-01-23
Airmedia HIGH 8.8
CVE-2022-40298

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the Ai…

Mitigation only
Fix from $1,950 2022-09-23
Airmedia HIGH 8.8
CVE-2022-34102

Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause th…

Mitigation only
Fix from $1,950 2022-09-13
Airmedia HIGH 7.8
CVE-2022-34101

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain…

Mitigation only
Fix from $1,950 2022-09-13
Airmedia HIGH 8.8
CVE-2022-34100

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level…

Mitigation only
Fix from $1,950 2022-09-13
Hd Md4x2 4k E Firmware CRITICAL 9.8
CVE-2022-23178EPSS 76%

An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthen…

No fix yet
Fix from $2,300 2022-01-15
Dm Nvx Dir 80 Firmware HIGH 7.5
CVE-2020-16839

On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthentic…

Mitigation only
Fix from $1,950 2021-07-30
Dmc Stro Firmware CRITICAL 9.8
CVE-2019-18184EPSS 8%

Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.

No fix yet
Fix from $2,300 2019-11-27
Am 100 Firmware CRITICAL 9.8
CVE-2019-3939

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interf…

Mitigation only
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.1
CVE-2019-3935

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requ…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware HIGH 7.8
CVE-2019-3937

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration optio…

No fix yet
Fix from $1,950 2019-04-30
Am 100 Firmware HIGH 7.8
CVE-2019-3938

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file gener…

No fix yet
Fix from $1,950 2019-04-30
Am 100 Firmware HIGH 7.5
CVE-2019-3936

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The …

Mitigation only
Fix from $1,950 2019-04-30
Am 100 Firmware MEDIUM 5.3
CVE-2019-3934EPSS 8%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST requ…

No fix yet
Fix from $1,600 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3925EPSS 7%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3926EPSS 7%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3927

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3932EPSS 36%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return…

No fix yet
Fix from $2,300 2019-04-30
Am 100 Firmware HIGH 8.8
CVE-2019-3931EPSS 6%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP re…

No fix yet
Fix from $1,950 2019-04-30
Am 100 Firmware MEDIUM 5.3
CVE-2019-3928

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.…

Mitigation only
Fix from $1,600 2019-04-30
Am 100 Firmware MEDIUM 5.3
CVE-2019-3933EPSS 6%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/bro…

No fix yet
Fix from $1,600 2019-04-30
Dm Txrx 100 Str Firmware CRITICAL 9.8
CVE-2016-5670

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes …

Mitigation only
Fix from $2,300 2016-08-03
Dm Txrx 100 Str Firmware CRITICAL 9.8
CVE-2016-5669

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL T…

Mitigation only
Fix from $2,300 2016-08-03
Dm Txrx 100 Str Firmware CRITICAL 9.8
CVE-2016-5668

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings vi…

Mitigation only
Fix from $2,300 2016-08-03
Dm Txrx 100 Str Firmware CRITICAL 9.8
CVE-2016-5667

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct request t…

Mitigation only
Fix from $2,300 2016-08-03
Dm Txrx 100 Str Firmware CRITICAL 9.8
CVE-2016-5666

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote atta…

Mitigation only
Fix from $2,300 2016-08-03