CVE-2023-38405: High severity Crestron Cp3n 6505417 Firmware vulnerability
Published Jul 17, 2023
·Updated
On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.
Affected Software
12 affected components
All of the following
Crestron Cp3n 6505417 Firmware<1.8001.0187
Crestron Cp3n 6505417
All of the following
Crestron Cp3 6504877 Firmware<1.8001.0187
Crestron Cp3 6504877
All of the following
Crestron Cp3-gv 6506034 Firmware<1.8001.0187
Crestron Cp3-gv 6506034
Crestron Cp3n 6505417 Firmware<1.8001.0187
Crestron Cp3n 6505417
Crestron Cp3 6504877 Firmware<1.8001.0187
Crestron Cp3 6504877
Crestron Cp3-gv 6506034 Firmware<1.8001.0187
Crestron Cp3-gv 6506034
Event History
Jul 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
09:15 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Crestron vulnerability?
The vulnerability ID for this Crestron vulnerability is CVE-2023-38405.
2
What is the severity level of CVE-2023-38405?
The severity level of CVE-2023-38405 is high.
3
How does CVE-2023-38405 affect Crestron control systems?
CVE-2023-38405 affects Crestron 3-Series Control Systems before 1.8001.0187, causing a crash when a specific BACnet packet is crafted and sent.
4
Which Crestron control systems are affected by CVE-2023-38405?
Crestron 3-Series Control Systems before 1.8001.0187 are affected by CVE-2023-38405.
5
How can I fix CVE-2023-38405?
To fix CVE-2023-38405, users should update their Crestron 3-Series Control Systems to version 1.8001.0187 or newer.