CVE-2016-5669: Critical severity crestron dm-txrx-100-str firmware vulnerability
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier for remote attackers to conduct man-in-the-middle attacks against HTTPS sessions by leveraging the certificate's trust relationship.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5669?
CVE-2016-5669 is classified as a high severity vulnerability due to its potential for facilitating man-in-the-middle attacks.
How do I fix CVE-2016-5669?
To fix CVE-2016-5669, upgrade the firmware of the Crestron DM-TXRX-100-STR device to version 1.3039.00040 or later.
What devices are affected by CVE-2016-5669?
CVE-2016-5669 affects Crestron DM-TXRX-100-STR devices running firmware versions before 1.3039.00040.
What type of attack does CVE-2016-5669 facilitate?
CVE-2016-5669 facilitates man-in-the-middle attacks on HTTPS sessions.
Is there a known public exploit for CVE-2016-5669?
As of now, there is no public exploit specifically reported for CVE-2016-5669.