CVE-2019-3910: Critical severity crestron airmedia vulnerability
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3910?
CVE-2019-3910 is a vulnerability that allows unauthenticated remote users to bypass authentication in the Crestron AM-100 web interface.
How does CVE-2019-3910 affect Crestron AM-100?
CVE-2019-3910 affects Crestron AM-100 before firmware version 1.6.0.2.
What is the severity of CVE-2019-3910?
CVE-2019-3910 has a severity rating of 9.1 (critical).
How can an unauthenticated remote user exploit CVE-2019-3910?
An unauthenticated remote user can exploit CVE-2019-3910 by using the authentication bypass in the web interface's return.cgi script.
Is there a fix available for CVE-2019-3910?
Yes, a fix for CVE-2019-3910 is available in firmware version 1.6.0.2 of Crestron AM-100.