← Back

CVE-2018-13341

nvd nist
Published: Aug 10, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.

Affected (2)

2 products
Tsw X60 Firmware
Mc3 Firmware
Configuration A
1 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Before 2.001.0037.001
Running on/withPlatform Versions
Crestron
Tsw 1060 B S
All versions
Crestron
Tsw 1060 Nc B S
All versions
Crestron
Tsw 1060 Nc W S
All versions
Crestron
Tsw 1060 W S
All versions
Crestron
Tsw 560 B S
All versions
Crestron
Tsw 560 Nc B S
All versions
Crestron
Tsw 560 Nc W S
All versions
Crestron
Tsw 560 W S
All versions
Crestron
Tsw 760 B S
All versions
Crestron
Tsw 760 Nc B S
All versions
Crestron
Tsw 760 Nc W S
All versions
Crestron
Tsw 760 W S
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.502.0047.00
Running on/withPlatform Versions
Crestron
Mc3
All versions

References (4)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.