First published: Tue Jul 27 2021(Updated: )
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Crestron Dm-nvx-dir-80 Firmware | =1.0.1.788 | |
Crestron Dm-nvx-dir-80 | ||
Crestron Dm-nvx-dir-160 Firmware | =1.0.1.788 | |
Crestron Dm-nvx-dir-160 | ||
Crestron Dm-nvx-dir-ent Firmware | =1.0.1.788 | |
Crestron Dm-nvx-dir-ent |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16839 is a vulnerability that allows an unauthenticated attacker to change the password on Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch.
CVE-2020-16839 has a severity rating of 7.5 (high).
Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch are affected by CVE-2020-16839.
An unauthenticated attacker can exploit CVE-2020-16839 by sending a WebSocket request to change the password on vulnerable devices.
To fix CVE-2020-16839, users should apply the DM-XIO/1-0-3-802 patch provided by Crestron.