First published: Fri Jan 18 2019(Updated: )
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Crestron Airmedia Am-100 Firmware | <1.6.0.2 | |
Crestron Airmedia AM-100 | ||
All of | ||
Crestron Airmedia Am-100 Firmware | <1.6.0.2 | |
Crestron Airmedia AM-100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3910 is a vulnerability that allows unauthenticated remote users to bypass authentication in the Crestron AM-100 web interface.
CVE-2019-3910 affects Crestron AM-100 before firmware version 1.6.0.2.
CVE-2019-3910 has a severity rating of 9.1 (critical).
An unauthenticated remote user can exploit CVE-2019-3910 by using the authentication bypass in the web interface's return.cgi script.
Yes, a fix for CVE-2019-3910 is available in firmware version 1.6.0.2 of Crestron AM-100.