Description
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.
Published: 2018-08-10
Score: 8.8 High
EPSS: 3.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-5288 Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.
History

No history.

Subscriptions

Crestron Mc3 Mc3 Firmware Tsw-1060-b-s Tsw-1060-nc-b-s Tsw-1060-nc-w-s Tsw-1060-w-s Tsw-560-b-s Tsw-560-nc-b-s Tsw-560-nc-w-s Tsw-560-w-s Tsw-760-b-s Tsw-760-nc-b-s Tsw-760-nc-w-s Tsw-760-w-s Tsw-x60 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-16T18:44:09.884Z

Reserved: 2018-07-05T00:00:00.000Z

Link: CVE-2018-13341

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-10T19:29:00.380

Modified: 2024-11-21T03:46:55.450

Link: CVE-2018-13341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses