PT-2017-18887 · Barco · Clickshare Base Unit

Published

2017-10-30

·

Updated

2019-10-03

·

CVE-2017-9377

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Barco ClickShare Base Unit devices with CSM-1 firmware versions prior to 1.7.0.3 Barco ClickShare Base Unit devices with CSC-1 firmware versions prior to 1.10.0.10
Description A command injection issue was identified, allowing an attacker with access to the product's web API to completely compromise the vulnerable device.
Recommendations For Barco ClickShare Base Unit devices with CSM-1 firmware versions prior to 1.7.0.3, update to version 1.7.0.3 or later to resolve the issue. For Barco ClickShare Base Unit devices with CSC-1 firmware versions prior to 1.10.0.10, update to version 1.10.0.10 or later to resolve the issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9377

Affected Products

Clickshare Base Unit