CVE Vulnerabilities

CVE-2019-3910

Published: Jan 18, 2019 | Modified: Aug 24, 2020
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
8.5 HIGH
AV:N/AC:L/Au:N/C:N/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interfaces return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

Affected Software

Name Vendor Start Version End Version
Airmedia_am-100_firmware Crestron * 1.6.0.2 (excluding)

References