CVE-2018-13341
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.
Affected (2)
Products: Crestron: Tsw X60 Firmware, Mc3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.001.0037.001 |
| Running on/with | Platform Versions |
|---|---|
Crestron Tsw 1060 B S | All versions |
Crestron Tsw 1060 Nc B S | All versions |
Crestron Tsw 1060 Nc W S | All versions |
Crestron Tsw 1060 W S | All versions |
Crestron Tsw 560 B S | All versions |
Crestron Tsw 560 Nc B S | All versions |
Crestron Tsw 560 Nc W S | All versions |
Crestron Tsw 560 W S | All versions |
Crestron Tsw 760 B S | All versions |
Crestron Tsw 760 Nc B S | All versions |
Crestron Tsw 760 Nc W S | All versions |
Crestron Tsw 760 W S | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.502.0047.00 |
| Running on/with | Platform Versions |
|---|---|
Crestron Mc3 | All versions |
References (4)
Source: cve@mitre.org
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource
Timeline
No history available yet.