Vulnerability Intelligence Report
CVE-2019-3927
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to change the admin or moderator user's password and gain access to restricted areas on the HTTP interface.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:2.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-284 ↗CWE-284 Improper Access Control
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Crestron | Crestron AirMedia | AM-100 firmware 1.6.0.2 and AM-101 firmware 2.7.0.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.167%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Tenable Network Security, Inc. · Vendor · USA |
| Reserved | 2019-01-03T00:00:00 |
| Published | 2019-04-30T20:15:32 |
| Last Updated | 2024-08-04T19:26:27 |
Community Chatter & Buzz