For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2018-08-10T19:00:00Z
Updated: 2024-09-16T16:52:46.583Z
Reserved: 2018-05-01T00:00:00
Link: CVE-2018-10630
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-08-10T19:29:00.240
Modified: 2024-11-21T03:41:41.853
Link: CVE-2018-10630
Redhat
No data.