CVE-2018-10630: Critical severity Crestron Tsw-x60 Firmware vulnerability
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-10630?
CVE-2018-10630 is a vulnerability in Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001.
What is the severity of CVE-2018-10630?
CVE-2018-10630 has a severity rating of 9.8 (critical).
How does CVE-2018-10630 affect Crestron TSW-X60?
CVE-2018-10630 affects Crestron TSW-X60 devices with version prior to 2.001.0037.001 by leaving the access to the CTP console open when compromised.
How does CVE-2018-10630 affect Crestron MC3?
CVE-2018-10630 affects Crestron MC3 devices with version prior to 1.502.0047.001 by leaving the access to the CTP console open when compromised.
How can I fix CVE-2018-10630?
To fix CVE-2018-10630, users need to enable authentication on Crestron TSW-X60 devices with version prior to 2.001.0037.001 and MC3 devices with version prior to 1.502.0047.001.