漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file generated via the "export configuration" feature. The configuration file is encrypted using the awenc binary. The same binary can be used to decrypt any configuration file since all the encryption logic is hard coded. A local attacker can use this vulnerability to gain access to devices username and passwords.
CVSS Information
N/A
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
Crestron Electronics AM-100和Crestron Electronics AM-101 信任管理问题漏洞
Vulnerability Description
Crestron Electronics AM-100和Crestron Electronics AM-101都是美国Crestron Electronics公司的一款智能家居网关产品。 带有固件1.6.0.2版本的Crestron AM-100和带有固件2.7.0.2版本的AM-101中存在信任管理问题漏洞。该漏洞源于网络系统或产品中缺乏有效的信任管理机制。攻击者可利用默认密码或者硬编码密码、硬编码证书等攻击受影响组件。
CVSS Information
N/A
Vulnerability Type
N/A