First published: Sat Jan 15 2022(Updated: )
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Crestron Hd-md4x2-4k-e Firmware | =1.0.0.2159 | |
Crestron HD-MD4X2-4K-E |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23178 is a vulnerability discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices that allows unauthorized access to user credentials through the administrative web interface.
CVE-2022-23178 has a severity level of 9.8 (critical).
CVE-2022-23178 affects Crestron HD-MD4X2-4K-E devices by exposing user credentials when the administrative web interface is accessed without authentication.
Yes, Crestron HD-MD4X2-4K-E 1.0.0.2159 firmware is affected by CVE-2022-23178.
There is currently no known fix for CVE-2022-23178. It is recommended to contact the vendor for updates or mitigation steps.