ZeroHour

CVE-2018-10630

CVSS 3.0
9.8 critical
EPSS
11%p96
Published
()
Modified
Description

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

Vendors
crestron
Products
tsw-x60 firmware, mc3 firmware
Weakness
CWE-284, CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.