Security Advisory

CVE-2025-47419

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-05-06 20:52:44
Last updated 2025-05-07 14:03:57
Assigner Crestron
CVSS score 10.0
State PUBLISHED

Description

Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.