CVE-2017-16709 describes a critical remote code execution vulnerability affecting Crestron Airmedia AM-100 devices with firmware prior to 1.6.0 and AM-101 devices with firmware prior to 2.7.0. This flaw allows remote authenticated administrators to execute arbitrary code through unspecified vectors, posing a significant risk to affected systems. The vulnerability carries a high CVSS score of 7.2, indicating a severe impact with high confidentiality, integrity, and availability compromise. Exploitation is straightforward, requiring only network access and high privileges, but does not involve user interaction. While not listed on the KEV catalog or Hot List, a Metasploit module (AwindInc SNMP Service Command Injection) is publicly available, demonstrating exploitability. Despite this, there is no recorded community discussion or media coverage, suggesting limited public awareness or active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.0CPE matchmatch criteria | cpe:2.3:o:crestron:airmedia_am-100_firmware:*:*:*:*:*:*:*:* | ||
< 2.7.0CPE matchmatch criteria | cpe:2.3:o:crestron:airmedia_am-101_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OEM Presentation Platform Vulnerabilities
Apr 30, 2019OEM Presentation Platform Vulnerabilities
Apr 30, 2019OEM Presentation Platform Vulnerabilities
Apr 30, 2019OEM Presentation Platform Vulnerabilities
Apr 30, 2019OEM Presentation Platform Vulnerabilities
Apr 30, 2019OEM Presentation Platform Vulnerabilities
Apr 30, 2019