Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpcf-99rm-ghcj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

EPSS

Процентиль: 90%
0.05464
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 7 лет назад

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

EPSS

Процентиль: 90%
0.05464
Низкий

9.1 Critical

CVSS3