peter bassill · operator
$ cve CVE-2018-10630 JSON

CVE-2018-10630

9.8
CRITICAL · CVSS 3.0 · EPSS 10.9% (pctl 96)

Patch early

EPSS 10.9% — above the 10% action threshold.

Description

For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.91% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2018-08-10
Last modified2026-06-17

Affected (15)

VendorProduct
crestronmc3
crestronmc3 firmware
crestrontsw-1060-b-s
crestrontsw-1060-nc-b-s
crestrontsw-1060-nc-w-s
crestrontsw-1060-w-s
crestrontsw-560-b-s
crestrontsw-560-nc-b-s
crestrontsw-560-nc-w-s
crestrontsw-560-w-s
crestrontsw-760-b-s
crestrontsw-760-nc-b-s
crestrontsw-760-nc-w-s
crestrontsw-760-w-s
crestrontsw-x60 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD