PT-2023-26409 · Crestron · Crestron 3-Series Control Systems

CVE-2023-38405

·

Published

2023-07-17

·

Updated

2024-10-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Crestron 3-Series Control Systems versions prior to 1.8001.0187
Description The issue allows an attacker to cause a crash by crafting and sending a specific BACnet packet.
Recommendations For Crestron 3-Series Control Systems versions prior to 1.8001.0187, update to version 1.8001.0187 or later to resolve the issue.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-38405

Affected Products

Crestron 3-Series Control Systems