CVE-2019-13379 describes a privilege escalation vulnerability in AVTECH Room Alert 3E devices running firmware versions prior to 2.2.5. An authenticated attacker with web interface access can reset the device to factory defaults, then log in with default administrator credentials. This vulnerability carries a high CVSS score of 8.8, indicating a high impact on confidentiality, integrity, and availability, with a low attack complexity. While the EPSS score suggests a relatively low probability of exploitation compared to other CVEs, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog. Community discussion and media coverage are minimal, with one article indirectly mentioning it in the context of broader cyberattacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.5CPE matchmatch criteria | cpe:2.3:o:avtech:room_alert_3e_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.