Overview
Crestron Electronics DM-TXRX-100-STR, version 1.2866.00026 and earlier, has a web management interface which contains multiple vulnerabilities, including authentication bypass, failure to restrict access to authorized users, use of hard-coded certificate, default credentials, and cross-site request forgery (CSRF). These vulnerabilities may be leveraged to gain complete control of affected devices.
Description
Crestron Electronics DM-TXRX-100-STR is a "streaming encoder/decoder designed to enable the distribution of high-definition AV signals over an IP network." The DM-TXRX-100-STR is configurable via a web interface that contains multiple vulnerabilities. CWE-603: Use of Client-Side Authentication - CVE-2016-5666 |
Impact
A remote, unauthenticated attacker may gain administrative access through numerous contexts to take complete control of vulnerable devices. |
Solution
Apply an upgrade |
Restrict network access and use strong passwords |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 10 | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 8.3 | E:F/RL:OF/RC:C |
Environmental | 6.2 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://www.crestron.com/downloads/pdf/spec_sheets/commercial_and_residential/dm-txrx-100-str.pdf
- https://cwe.mitre.org/data/definitions/603.html
- http://cwe.mitre.org/data/definitions/425.html
- https://cwe.mitre.org/data/definitions/306.html
- https://cwe.mitre.org/data/definitions/321.html
- https://cwe.mitre.org/data/definitions/255.html
- https://cwe.mitre.org/data/definitions/352.html
- https://www.crestron.com/resources/resource-library/firmware
Acknowledgements
Thanks to Carsten Eiram of Risk Based Security for reporting these vulnerabilities.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2016-5666, CVE-2016-5667, CVE-2016-5668, CVE-2016-5669, CVE-2016-5670, CVE-2016-5671 |
Date Public: | 2016-08-01 |
Date First Published: | 2016-08-01 |
Date Last Updated: | 2016-08-01 16:05 UTC |
Document Revision: | 24 |