Skip to main content

Vendor archive

crestron CVEs

Beta · best-effort

40 CVEs tagged to vendor crestron21 Critical, 15 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-6926

Published Jan 23, 2024

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privilege…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40298

Published Sep 23, 2022

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, ve…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34102

Published Sep 13, 2022

Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can pause the uninstallation of an executa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34101

Published Sep 13, 2022

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place a malicious DLL in a certain path to execute code and pref…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34100

Published Sep 13, 2022

A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a low-privileged user can gain a SYSTEM level command prompt by pre-staging…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2