CVE-2017-16709
high · 7.2Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors.
7.2
CVSS
72.0%
EPSS (exploit prob.)
99th
EPSS percentile
2018-07-11
Published
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| crestron | airmedia_am-100_firmware | < 1.6.0 |
| crestron | airmedia_am-100 | all versions |
| crestron | airmedia_am-101_firmware | < 2.7.0 |
| crestron | airmedia_am-101 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/154362/AwindInc-SNMP-Service-Command-Injection.html
- https://support.crestron.com/app/answers/answer_view/a_id/5471/~/the-latest-details-from-crestron-on-security-and-safety-on-the-internet#CVE-2017-16709
- https://www.tenable.com/security/research/tra-2019-20
- http://packetstormsecurity.com/files/154362/AwindInc-SNMP-Service-Command-Injection.html
- https://support.crestron.com/app/answers/answer_view/a_id/5471/~/the-latest-details-from-crestron-on-security-and-safety-on-the-internet#CVE-2017-16709
- https://www.tenable.com/security/research/tra-2019-20
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-16709