CVE Vulnerabilities

CVE-2016-5666

Published: Aug 03, 2016 | Modified: Aug 15, 2016
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attackers to obtain access by setting the value of objresp.authenabled to 1.

Affected Software

Name Vendor Start Version End Version
Dm-txrx-100-str_firmware Crestron 1.2866.00026 (including) 1.2866.00026 (including)

References