CVE-2019-3934
- EPSS 0.41%
- Veröffentlicht 30.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:53
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulnerability to download the curre...
CVE-2019-3935
- EPSS 1.7%
- Veröffentlicht 30.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:53
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop,...
CVE-2019-3936
- EPSS 1.82%
- Veröffentlicht 30.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:54
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 is vulnerable to denial of service via a crafted request to TCP port 389. The request will force the slideshow to transition into a "stopped" state. A remote, unauthenticated atta...
CVE-2019-3937
- EPSS 0.02%
- Veröffentlicht 30.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:54
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuration options in cleartext in the file /tmp/scfgdndf. A local attacker can use this vulnerability to recover sen...
CVE-2019-3938
- EPSS 0.03%
- Veröffentlicht 30.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:54
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the awenc bina...
CVE-2019-3939
- EPSS 4.23%
- Veröffentlicht 30.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:54
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the d...
- EPSS 30.5%
- Veröffentlicht 30.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:52
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.9.3. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands...
- EPSS 30.5%
- Veröffentlicht 30.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:52
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system command...
CVE-2019-3927
- EPSS 2.15%
- Veröffentlicht 30.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:52
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can ...
CVE-2019-3928
- EPSS 1.28%
- Veröffentlicht 30.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:52
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.100.3.2.7.4 OIDs. A remote, unauthenticated attacker can use this vulnerability to access a restricte...