CVE-2017-16710: XSS
Published Jul 11, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected components
Crestron Airmedia Am-100 Firmware<1.6.0
Crestron AirMedia AM-100
Crestron Airmedia Am-101 Firmware<2.7.0
Crestron Airmedia Am-101
Event History
Jul 11, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16710?
The severity of CVE-2017-16710 is medium with a score of 4.8.
2
How does CVE-2017-16710 affect Crestron Airmedia AM-100 devices?
CVE-2017-16710 affects Crestron Airmedia AM-100 devices with firmware versions before 1.6.0.
3
How does CVE-2017-16710 affect Crestron Airmedia AM-101 devices?
CVE-2017-16710 affects Crestron Airmedia AM-101 devices with firmware versions before 2.7.0.
4
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2017-16710.
5
How can I fix CVE-2017-16710?
To fix CVE-2017-16710, update the firmware of Crestron Airmedia AM-100 devices to version 1.6.0 or later, and Crestron Airmedia AM-101 devices to version 2.7.0 or later.