PT-2019-16786 · Crestron · Crestron Am-100+1
Published
2019-04-30
·
Updated
2022-12-06
·
CVE-2019-3932
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Crestron AM-100 version 1.6.0.2
Crestron AM-101 version 2.7.0.2
Description
The issue is related to authentication bypass due to a hard-coded password in the return.tgi file. A remote, unauthenticated attacker can exploit this to control external devices via the uart bridge.
Recommendations
For Crestron AM-100 version 1.6.0.2, consider disabling the uart bridge functionality until a patch is available.
For Crestron AM-101 version 2.7.0.2, restrict access to the return.tgi file to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crestron Am-100
Crestron Am-101