Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3910

Опубликовано: 18 янв. 2019
Источник: nvd
CVSS3: 9.1
CVSS2: 8.5
EPSS Низкий

Описание

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:crestron:airmedia_am-100_firmware:*:*:*:*:*:*:*:*
Версия до 1.6.0.2 (исключая)
cpe:2.3:h:crestron:airmedia_am-100:-:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05464
Низкий

9.1 Critical

CVSS3

8.5 High

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.

EPSS

Процентиль: 90%
0.05464
Низкий

9.1 Critical

CVSS3

8.5 High

CVSS2

Дефекты

NVD-CWE-noinfo