216.73.217.22

CVE-2025-47419

· Published 06/05/2025 21:16 · Modified 06/05/2025 21:16

Labels: CVE-2025-47419 2025-05-0625b0b659-c4b4-483f-aecb-067757d23ef3CVE-2025-47419CWE-319

Essential information

Published
06/05/2025 21:16
Modified
06/05/2025 21:16
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
25b0b659-c4b4-483f-aecb-067757d23ef3
NVD
View on NVD

Affected products (CPE)

ProductCPE
crestron / automate vx cpe:2.3:a:crestron:automate_vx:5.6.8161.21536-6.4.0.49:*:*:*:*:*:*:*

References