- How many CVEs does Crestron have?
- Crestron has 49 published CVE records since 2016, including 8 in the last two years.
- How many Crestron CVEs are in CISA KEV?
- Yes — 1 of Crestron's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which Crestron products have the most CVEs?
- The Crestron products with the most published CVEs are am-101 firmware, am-100, am-100 firmware, am-101, Crestron AirMedia.
- What are the most common weakness types in Crestron CVEs?
- Crestron's CVEs most often map to these CWE weakness types: CWE-284 (Improper Access Control), CWE-88 (Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor).
- Are there public exploits for Crestron vulnerabilities?
- Yes — 6 of Crestron's CVEs have a known public exploit.
- How many critical Crestron vulnerabilities are there?
- Crestron has 23 critical and 18 high-severity CVEs.
- What is the average severity of Crestron CVEs?
- The average CVSS base score across Crestron's scored CVEs is 8.4.