CVE-2018-5553
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.
Affected (3)
Products: Crestron: Dge 100 Firmware, Dm Dge 200 C Firmware, Ts 1542 C Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3384.00049.001 |
| Running on/with | Platform Versions |
|---|---|
Crestron Dge 100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3384.00049.001 |
| Running on/with | Platform Versions |
|---|---|
Crestron Dm Dge 200 C | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3384.00049.001 |
| Running on/with | Platform Versions |
|---|---|
Crestron Ts 1542 C | All versions |
References (4)
Source: cve@rapid7.com
Third Party Advisory
Source: cve@rapid7.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.