CVE-2016-5667: Critical severity crestron dm-txrx-100-str firmware vulnerability
Published Aug 3, 2016
·Updated
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct request to a page other than index.html.
Affected Software
2 affected components
Crestron Dm-txrx-100-str Firmware=1.2866.00026
Crestron DM-TXRX-100-STR
Event History
Aug 3, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5667?
CVE-2016-5667 has been assigned a medium severity level due to its potential for remote authentication bypass.
2
How do I fix CVE-2016-5667?
To fix CVE-2016-5667, update the firmware of the Crestron DM-TXRX-100-STR device to version 1.3039.00040 or later.
3
What type of attack is CVE-2016-5667 vulnerable to?
CVE-2016-5667 is vulnerable to remote attacks that exploit authentication bypass through direct requests.
4
Which devices are affected by CVE-2016-5667?
CVE-2016-5667 affects Crestron DM-TXRX-100-STR devices with firmware versions prior to 1.3039.00040.
5
Is CVE-2016-5667 still a risk if I upgrade my firmware?
After upgrading to firmware version 1.3039.00040 or higher, the risk associated with CVE-2016-5667 is mitigated.