Skip to content
COOEY

EXPOSURES › CVE-2019-3929

CVE-2019-3929

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-3929 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Crestron products allow remote, unauthenticated attackers to execute OS commands as root via command injection on the file_transfer.cgi endpoint.

A remote, unauthenticated attacker can exploit this command injection flaw to run arbitrary OS commands with root privileges, enabling full system compromise and lateral movement. For DIB organizations, this represents a critical RCE vulnerability that bypasses authentication controls and violates CMMC/NIST 800-171 requirements for protecting systems and information. Organizations must immediately patch Crestron products and restrict network access to unpatched systems.

Shame score — A remote, unauthenticated command injection flaw allowing root-level OS command execution is a severe, avoidable vulnerability that was actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.