CVE-2023-38405: Crestron CP3-Gv 6506034 Firmware

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.

Affected products

  • Crestron CP3-Gv 6506034 Firmware: before 1.8001.0187 (fixed in 1.8001.0187)
  • Crestron CP3 6504877 Firmware: before 1.8001.0187 (fixed in 1.8001.0187)
  • Crestron CP3N 6505417 Firmware: before 1.8001.0187 (fixed in 1.8001.0187)

Published 2023-07-17. Last modified 2026-06-17.