CVE-2018-5553: Crestron DGE-100 Console Command Injection (FIXED)
The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Crestron DGE-100 Console service (DGE-100, DM-DGE-200-C, TS-1542-C)to a version that resolves this vulnerability.Fixed in 1.3384.00059.001
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-5553.
What is the severity of CVE-2018-5553?
The severity of CVE-2018-5553 is critical with a score of 9.8.
Which devices are affected by CVE-2018-5553?
Devices running Crestron Console service DGE-100, DM-DGE-200-C, and TS-1542-C with firmware versions 1.3384.00049.001 and lower are affected.
How can this vulnerability be exploited?
This vulnerability can be exploited through command injection to gain root-level access.
Are there any fixes or patches available for this vulnerability?
Yes, fixes for CVE-2018-5553 are available. Please refer to the references for more details.