CVE-2020-16839
On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request.
Published:Jul 27, 2021
Last Modified:Nov 21, 2024
EPS:Jul 27, 2021
EPSS Score:0.00234
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Crestron
Product
Dm-nvx-dir-160
Crestron
Dm-nvx-dir-160
Vendor
Crestron
Product
Dm-nvx-dir-160 Firmware
Crestron
Dm-nvx-dir-160 Firmware
Vendor
Crestron
Product
Dm-nvx-dir-80
Crestron
Dm-nvx-dir-80
Vendor
Crestron
Product
Dm-nvx-dir-80 Firmware
Crestron
Dm-nvx-dir-80 Firmware
Vendor
Crestron
Product
Dm-nvx-dir-ent
Crestron
Dm-nvx-dir-ent
Vendor
Crestron
Product
Dm-nvx-dir-ent Firmware
Crestron
Dm-nvx-dir-ent Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
