First published: Fri Aug 10 2018(Updated: )
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Crestron Tsw-x60 Firmware | <2.001.0037.001 | |
Crestron Tsw-1060-b-s | ||
Crestron Tsw-1060-nc-b-s | ||
Crestron Tsw-1060-nc-w-s | ||
Crestron Tsw-1060-w-s | ||
Crestron Tsw-560-b-s | ||
Crestron Tsw-560-nc-b-s | ||
Crestron Tsw-560-nc-w-s | ||
Crestron Tsw-560-w-s | ||
Crestron Tsw-760-b-s | ||
Crestron Tsw-760-nc-b-s | ||
Crestron Tsw-760-nc-w-s | ||
Crestron Tsw-760-w-s | ||
Crestron Mc3 Firmware | <1.502.0047.00 | |
Crestron Mc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13341 is a vulnerability in Crestron TSW-X60 firmware and MC3 firmware that allows attackers to decipher passwords for special sudo accounts.
The severity of CVE-2018-13341 is high, with a CVSS score of 8.8.
Attackers can exploit CVE-2018-13341 by using information accessible to those with regular user privileges to calculate passwords for special sudo accounts.
To fix CVE-2018-13341, update the Crestron TSW-X60 firmware to version 2.001.0037.001 or later, and update the MC3 firmware to version 1.502.0047.00 or later.
You can find more information about CVE-2018-13341 at the following references: [1] http://www.securityfocus.com/bid/105051 [2] https://ics-cert.us-cert.gov/advisories/ICSA-18-221-01