ZeroHour

CVE-2019-13379

PoC ×2
CVSS 3.0
8.8 high
EPSS
3%p86
Published
()
Modified
Description

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

Vendors
avtech
Products
room alert 3e firmware
Weakness
CWE-668
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.