9.8
CVSSv3

CVE-2016-5669

Published: 03/08/2016 Updated: 15/08/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Crestron Electronics DM-TXRX-100-STR devices with firmware prior to 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier for remote malicious users to conduct man-in-the-middle attacks against HTTPS sessions by leveraging the certificate's trust relationship.

Vulnerable Product Search on Vulmon Subscribe to Product

crestron dm-txrx-100-str_firmware 1.2866.00026