CVE-2019-3937: High severity crestron airmedia am-100 firmware vulnerability
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to recover sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Crestron AM-100 and AM-101 firmware issue?
The vulnerability ID is CVE-2019-3937.
What is the severity of CVE-2019-3937?
The severity of CVE-2019-3937 is high with a CVSS score of 7.8.
Which Crestron devices are affected by CVE-2019-3937?
The Crestron AM-100 firmware version 1.6.0.2 and Crestron AM-101 firmware version 2.7.0.2 are affected.
What is the impact of CVE-2019-3937?
The vulnerability allows a local attacker to recover sensitive data, including usernames, passwords, slideshow passcode, and configuration options.
How can I mitigate CVE-2019-3937?
Update the firmware of Crestron AM-100 to version 1.6.0.3 or later, and update the firmware of Crestron AM-101 to version 2.7.0.3 or later.