Security Advisory
CVE-2019-13379
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the devices web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.