Vulnerability Details CVE-2018-11229
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protocol (CTP).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.046
EPSS Ranking 88.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-11229
-
cpe:2.3:h:crestron:dmc-str:-
-
cpe:2.3:h:crestron:tsw-1060-nc:-
-
cpe:2.3:h:crestron:tsw-1060:-
-
cpe:2.3:h:crestron:tsw-560-nc:-
-
cpe:2.3:h:crestron:tsw-560:-
-
cpe:2.3:h:crestron:tsw-760-nc:-
-
cpe:2.3:h:crestron:tsw-760:-
-
cpe:2.3:o:crestron:crestron_toolbox_protocol_firmware:1.502.0047.001