Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2018-07-11T16:29:00.517
2024-11-21T03:16:50.043
Modified
CVSSv3.0: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | crestron | airmedia_am-100_firmware | < 1.6.0 | Yes |
Hardware | crestron | airmedia_am-100 | - | No |
Operating System | crestron | airmedia_am-101_firmware | < 2.7.0 | Yes |
Hardware | crestron | airmedia_am-101 | - | No |