// For flags

CVE-2016-5669

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier for remote attackers to conduct man-in-the-middle attacks against HTTPS sessions by leveraging the certificate's trust relationship.

Dispositivos Crestron Electronics DM-TXRX-100-STR con firmware en versiones anteriores a 1.3039.00040 usa un certificado codificado 0xb9eed4d955a59eb3 X.509 de un OpenSSL Test Certification Authority, lo que facilita a atacantes remotos llevar a cabo ataques man-in-the-middle contra sesiones HTTPS mediante el aprovechamiento de la relaciĆ³n de confianza del certificado.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-06-16 CVE Reserved
  • 2016-08-03 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (2)
URL Tag Source
http://www.kb.cert.org/vuls/id/974424 Third Party Advisory
http://www.securityfocus.com/bid/92211 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Crestron
Search vendor "Crestron"
Dm-txrx-100-str Firmware
Search vendor "Crestron" for product "Dm-txrx-100-str Firmware"
1.2866.00026
Search vendor "Crestron" for product "Dm-txrx-100-str Firmware" and version "1.2866.00026"
-
Affected
in Crestron
Search vendor "Crestron"
Dm-txrx-100-str
Search vendor "Crestron" for product "Dm-txrx-100-str"
--
Safe