CRITICAL · 9.8

CVE-2019-3929

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firm...

Vulnerability Description

The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CrestronAm-100 Firmware1.6.0.2
CrestronAm-100-
CrestronAm-101 Firmware2.7.0.2
CrestronAm-101-
BarcoWepresent Wipg-1000P Firmware2.3.0.10
BarcoWepresent Wipg-1000P-
BarcoWepresent Wipg-1600W Firmware< 2.4.1.19
BarcoWepresent Wipg-1600W-
ExtronSharelink 200 Firmware2.0.3.4
ExtronSharelink 200-
ExtronSharelink 250 Firmware2.0.3.4
ExtronSharelink 250-
TeqavitWips710 Firmware1.1.0.7
TeqavitWips710-
SharpPn-L703Wa Firmware1.4.2.3
SharpPn-L703Wa-
OptomaWps-Pro Firmware1.0.0.5
OptomaWps-Pro-
BlackboxHd Wireless Presentation System Firmware1.0.0.5
BlackboxHd Wireless Presentation System-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-3929?

CVE-2019-3929 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firm...

How severe is CVE-2019-3929?

CVE-2019-3929 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2019-3929?

Check the references section above for vendor advisories and patch information. Affected products include: Crestron Am-100 Firmware, Crestron Am-100, Crestron Am-101 Firmware, Crestron Am-101, Barco Wepresent Wipg-1000P Firmware.