CVE-2018-11228
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
08/06/2018
Last modified:
02/05/2019
Description
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:crestron:crestron_toolbox_protocol_firmware:*:*:*:*:*:*:*:* | 2.001.0037.001 (excluding) | |
| cpe:2.3:h:crestron:dmc-str:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:crestron:tsw-1060:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:crestron:tsw-1060-nc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:crestron:tsw-560:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:crestron:tsw-560-nc:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:crestron:tsw-760:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:crestron:tsw-760-nc:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



