PT-2019-19313 · British Airways · British Airways Entertainment System
Published
2019-02-22
·
Updated
2019-02-26
·
CVE-2019-9019
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
British Airways Entertainment System (affected versions not specified)
Description
The issue concerns the British Airways Entertainment System, which does not prevent the USB charging/data-transfer feature from interacting with USB keyboard and mouse devices. This allows physically proximate attackers to conduct unanticipated attacks against Entertainment applications. For example, using mouse copy-and-paste actions can trigger a Chat buffer overflow, potentially having other unspecified impacts.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
British Airways Entertainment System