CVE-2017-9377

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:barco:clickshare_csm-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_csm-1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:barco:clickshare_csc-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_csc-1:-:*:*:*:*:*:*:*

Information

Published : 2017-10-30 07:29

Updated : 2019-10-02 17:03


NVD link : CVE-2017-9377

Mitre link : CVE-2017-9377


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

barco

  • clickshare_csm-1
  • clickshare_csc-1_firmware
  • clickshare_csm-1_firmware
  • clickshare_csc-1