PT-2025-19988 · Crestron · Crestron Automate Vx

CVE-2025-47417

·

Publicado

2025-05-06

·

Atualizado

2025-05-06

CVSS v4.0

5.1

Média

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Crestron Automate VX versions 5.6.8161.21536 through 6.4.0.49
Description The issue allows exposure of sensitive information to an unauthorized actor, enabling functionality misuse. When the Enable Debug Images feature in Crestron Automate VX is active, snapshots of captured video or portions thereof are stored locally on the system without any visible indication.
Recommendations For Crestron Automate VX versions 5.6.8161.21536 through 6.4.0.49, consider disabling the Enable Debug Images feature to prevent unauthorized access to sensitive information until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-47417

Produtos afetados

Crestron Automate Vx