Vulnerability Intelligence Report
CVE-2019-3939
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:2.76%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-16 ↗CWE-16: Default Credentials
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Crestron | Crestron AirMedia | AM-100 firmware 1.6.0.2 and AM-101 firmware 2.7.0.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.764%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Tenable Network Security, Inc. · Vendor · USA |
| Reserved | 2019-01-03T00:00:00 |
| Published | 2019-04-30T20:40:18 |
| Last Updated | 2024-08-04T19:26:27 |
Community Chatter & Buzz