CVE-2022-23178
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.
Published:Jan 15, 2022
Last Modified:Nov 21, 2024
EPS:Jan 15, 2022
EPSS Score:0.92757
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Crestron
Product
Hd-md4x2-4k-e
Crestron
Hd-md4x2-4k-e
Vendor
Crestron
Product
Hd-md4x2-4k-e Firmware
Crestron
Hd-md4x2-4k-e Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
