First published: Tue Jan 23 2024(Updated: )
There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Crestron AM-300 firmware | =1.4499.00018 | |
Crestron AM-300 |
Crestron has resolved this vulnerability in firmware version 1.4499.00023.001 or higher. Please see https://security.crestron.com https://security.crestron.com/ or contact True Blue Support for additional information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.