First published: Tue Jul 10 2018(Updated: )
The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Crestron Dge-100 Firmware | <=1.3384.00049.001 | |
Crestron Dge-100 | ||
Crestron Dm-dge-200-c Firmware | <=1.3384.00049.001 | |
Crestron Dm-dge-200-c | ||
Crestron Ts-1542-c Firmware | <=1.3384.00049.001 | |
Crestron Ts-1542-c |
Users should update affected devices to the latest firmware version (1.3384.00059.001 or higher) available from Crestron's product pages.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-5553.
The severity of CVE-2018-5553 is critical with a score of 9.8.
Devices running Crestron Console service DGE-100, DM-DGE-200-C, and TS-1542-C with firmware versions 1.3384.00049.001 and lower are affected.
This vulnerability can be exploited through command injection to gain root-level access.
Yes, fixes for CVE-2018-5553 are available. Please refer to the references for more details.