CVE-2018-13341
Estado: ModificadaAlta (8.8)—
Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.70%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-13341",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-08-10T19:29:00.380",
"references": [
{
"url": "http://www.securityfocus.com/bid/105051",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-221-01",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/105051",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-221-01",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges."
},
{
"lang": "es",
"value": "Para las versiones anteriores a la 2.001.0037.001 de Crestron TSW-X60 y las versiones anteriores a la 1.502.0047.001 de MC3, las contraseñas para las cuentas sudo especiales podrían calcularse mediante información accesible a aquellos que tengan privilegios de usuario regular. Los atacantes podrían descifrar estas contraseñas, lo que les permitiría ejecutar llamadas ocultas a la API y escapar del entorno de la consola CTP con privilegios elevados."
}
],
"lastModified": "2026-06-17T01:39:14.647",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:crestron:tsw-x60_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0C26C6C-4F6D-4084-AA36-CDBBF5B182F0",
"versionEndExcluding": "2.001.0037.001"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:crestron:tsw-1060-b-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5B827C62-5712-4511-8506-74B925DA053B"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-1060-nc-b-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D41EF7B1-8F7A-4F66-B9B1-90405F507FE8"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-1060-nc-w-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "28A41D87-44CE-452D-A696-5DFCAEFF3D4C"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-1060-w-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BCAC6D4C-51C5-4687-B9F5-8B3FD9F4503E"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-560-b-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A7B4BBE9-C4D1-42C1-AD23-3F47D2E7BCD4"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-560-nc-b-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "621667FD-7FC9-4606-857B-2423EAEF613A"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-560-nc-w-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "30C58417-CA62-4E68-8421-A968406F4797"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-560-w-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5A888FB2-6F71-4D45-9E03-505DAD49909A"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-760-b-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "01970CD6-3FE7-42BF-A2BB-358692F8B787"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-760-nc-b-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "507A0431-6EB0-4535-AD17-97C09542AB6E"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-760-nc-w-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B084CEC7-E1B0-44F1-AAAB-CEC86EA767AF"
},
{
"criteria": "cpe:2.3:h:crestron:tsw-760-w-s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5FBE392B-4A2B-4B7E-9F1D-6E55FCE0146C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:crestron:mc3_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A80A1FEE-30EF-43E2-8AE9-895E18F4DDB1",
"versionEndExcluding": "1.502.0047.00"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:crestron:mc3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3E648452-F573-478D-9A32-1D76534926D4"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}