CVE-2023-6926

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
23/01/2024
Last modified:
29/01/2024

Description

<br /> There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate their privileges to root-level access.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:crestron:am-300_firmware:1.4499.00018:*:*:*:*:*:*:*
cpe:2.3:h:crestron:am-300:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools