CVE-2019-3927: Critical severity crestron airmedia am-100 firmware vulnerability
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to change the admin or moderator user's password and gain access to restricted areas on the HTTP interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3927?
CVE-2019-3927 is a vulnerability in Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 that allows anyone to change the administrator and moderator passwords.
How can an attacker exploit CVE-2019-3927?
A remote, unauthenticated attacker can exploit CVE-2019-3927 by using the vulnerabilities associated with iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs to change the admin or moderator passwords.
What is the severity of CVE-2019-3927?
CVE-2019-3927 has a severity rating of 9.8 (Critical).
Which versions of Crestron AM-100 and AM-101 are affected by CVE-2019-3927?
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are affected by CVE-2019-3927.
Is CVE-2019-3927 a common vulnerability?
CVE-2019-3927 is a critical vulnerability and should be treated with urgency.