CVE-2020-16839: High severity crestron dm nvx director vulnerability
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-16839?
CVE-2020-16839 is a vulnerability that allows an unauthenticated attacker to change the password on Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch.
How severe is CVE-2020-16839?
CVE-2020-16839 has a severity rating of 7.5 (high).
Which devices are affected by CVE-2020-16839?
Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch are affected by CVE-2020-16839.
How can an attacker exploit CVE-2020-16839?
An unauthenticated attacker can exploit CVE-2020-16839 by sending a WebSocket request to change the password on vulnerable devices.
How can I fix CVE-2020-16839?
To fix CVE-2020-16839, users should apply the DM-XIO/1-0-3-802 patch provided by Crestron.