CVE-2019-13379
Last modified
CVE-2019-13379 is a vulnerability of currently unknown severity. On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.. EPSS estimates a 3.00% chance of exploitation in the next 30 days.
Description
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avtech | Room Alert 3e Firmware | < 2.2.5 |
References
- https://jordonlovik.wordpress.com/2019/07/06/roomalert-by-avtech-critical-vulnerability-disclosure/Exploit, Third Party Advisory
- https://www.youtube.com/watch?v=X1PY7kMFkVgExploit, Third Party Advisory
- https://jordonlovik.wordpress.com/2019/07/06/roomalert-by-avtech-critical-vulnerability-disclosure/Exploit, Third Party Advisory
- https://www.youtube.com/watch?v=X1PY7kMFkVgExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13379?
How severe is CVE-2019-13379?
How do I fix CVE-2019-13379?
Are you affected by CVE-2019-13379?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
