PT-2022-18149 · Barco · Transform N+1

Published

2022-06-01

·

Updated

2023-08-08

·

CVE-2022-26971

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Barco Control Room Management Suite web application, which is part of TransForm N versions prior to 3.14
Description The issue concerns the exposure of a license file upload mechanism in the web application without requiring authentication. This allows unauthorized access to upload files.
Recommendations For versions prior to 3.14, consider disabling the license file upload mechanism until a patch is available to prevent unauthorized access. Restrict access to the upload feature to minimize the risk of exploitation.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-26971

Affected Products

Barco Control Room Management Suite
Transform N