CVE-2019-13379
07.07.2019, 16:15
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.Enginsight
Vendor | Product | Version |
---|---|---|
avtech | room_alert_3e_firmware | 𝑥 < 2.2.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References