• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-3935
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2022-12-06
N/A
9.1 CRITICAL
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop, and disconnect active slideshows.
CVE-2019-3934
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2020-10-16
N/A
5.3 MEDIUM
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulnerability to download the current slide image without knowing the access code.
CVE-2019-3933
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2020-10-16
N/A
5.3 MEDIUM
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this vulnerability to watch a slideshow without knowing the access code.
CVE-2019-3932
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2022-12-06
N/A
9.8 CRITICAL
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.
CVE-2019-3931
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2020-10-16
N/A
8.8 HIGH
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to upload files to the device and ultimately execute code as root.
CVE-2019-3930
Optoma, Wps-pro Firmware
Wps-pro_firmware, Wps-pro
2020-10-16
N/A
9.8 CRITICAL
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.
CVE-2019-3929
Optoma, Wps-pro Firmware
Wps-pro_firmware, Wps-pro
2020-10-16
N/A
9.8 CRITICAL
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
CVE-2019-3928
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2022-12-08
N/A
5.3 MEDIUM
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcode via the iso.3.6.1.4.1.3212.100.3.2.7.4 OIDs. A remote, unauthenticated attacker can use this vulnerability to access a restricted presentation or to become the presenter.
CVE-2019-3927
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2020-10-16
N/A
9.8 CRITICAL
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator passwords via the iso.3.6.1.4.1.3212.100.3.2.8.1 and iso.3.6.1.4.1.3212.100.3.2.8.2 OIDs. A remote, unauthenticated attacker can use this vulnerability to change the admin or moderator user's password and gain access to restricted areas on the HTTP interface.
CVE-2019-3926
Am-101, Am-101 Firmware, Crestron
Dmc-stro_firmware, Dmc-stro, Airmedia_am-100_firmware, Airmedia_am-100, Am-100_firmware, Am-100, Am-101_firmware, Am-101
2020-10-16
N/A
9.8 CRITICAL
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID iso.3.6.1.4.1.3212.100.3.2.14.1. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.
« Previous 1 … 5,520 5,521 5,522 5,523 5,524 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE