PT-2021-10089 · Barco · Barco Transform Ndn-210 Pro+3
Published
2021-01-07
·
Updated
2021-01-13
·
CVE-2020-17500
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro versions prior to 3.8
Description:
The issue affects the web administration panel of the Barco TransForm NDN-210, which uses basic authentication over https. There is a command injection issue in the
username and password fields of the logon prompt, resulting in unauthenticated remote code execution. The NDN-210 is part of the Barco TransForm N solution.Recommendations:
For Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro versions prior to 3.8, update to version 3.8 or later to resolve the issue.
As a temporary workaround, consider restricting access to the web administration panel to minimize the risk of exploitation.
Avoid using the
username and password fields in the logon prompt until the issue is resolved.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barco Transform Ndn-210 Lite
Barco Transform Ndn-210 Pro
Barco Transform Ndn-211 Lite
Barco Transform Ndn-211 Pro