OEM Presentation Platform Vulnerabilities

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Synopsis Tenable found multiple vulnerabilities while investigating a Crestron AM-100. Tenable also discovered that the Crestron AM-100 shared a code base with the Barco wePresent, Extron ShareLink, InFocus LiteShow, TEQ AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, and possibly others. The vulnerabilities listed below do not affect all devices. Tenable has done its best to specifically call out which platforms are affected by each vulnerability. ### CVE-2019-3925: SNMP Command Injection #1 A remote, unauthenticated attacker can inject operating system commands on the Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2. The vulnerability occurs over SNMP via the iso.3.6.1.4.1.3212.100.3.2.9.3 OID. The command injection is the result of shelling out to /bin/ftpfw.sh. ![](https://images.seebug.org/1560151460666-w331s) ### CVE-2019-3926: SNMP Command Injection #2 A remote, unauthenticated attacker can inject operating system commands on...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息