CVE-2018-10630

CVE-2018-10630

Vendor Ics-Cert
Product Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001
Weakness CWE-284
Published August 10, 2018
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

Key dates

02Disclosure timeline

August 10, 2018 CVE published
September 16, 2024 Record updated