PT-2019-19313 · British Airways · British Airways Entertainment System

Published

2019-02-22

·

Updated

2019-02-26

·

CVE-2019-9019

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions British Airways Entertainment System (affected versions not specified)
Description The issue concerns the British Airways Entertainment System, which does not prevent the USB charging/data-transfer feature from interacting with USB keyboard and mouse devices. This allows physically proximate attackers to conduct unanticipated attacks against Entertainment applications. For example, using mouse copy-and-paste actions can trigger a Chat buffer overflow, potentially having other unspecified impacts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9019

Affected Products

British Airways Entertainment System