Barco
Barco Control Room Management Suite: vulnerabilidades y CVE
Barco Control Room Management Suite tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-26978 | Media (6.1) | 0.57% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS. |
| CVE-2022-26977 | Media (6.1) | 0.57% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS. |
| CVE-2022-26976 | Media (5.4) | 0.45% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS. |
| CVE-2022-26975 | Alta (7.5) | 1.0% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication. |
| CVE-2022-26974 | Media (6.1) | 0.57% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS. |
| CVE-2022-26973 | Media (5.3) | 0.77% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal… |
| CVE-2022-26972 | Media (6.1) | 0.57% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS. |
| CVE-2022-26971 | Media (5.3) | 0.73% | — | 2 jun 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication. |
| CVE-2022-26233 | Alta (7.5) | 15% | — | 3 abr 2022 | Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET… |
Otros productos de Barco
Clickshare Cse-200 Firmware · 9Wepresent Wipg-1600w Firmware · 8Clickshare Csc-1 Firmware · 6Clickshare Cs-100 Firmware · 6Clickshare Cse-800 Firmware · 5Clickshare Cse-200+ Firmware · 5Clickshare Button R9861500d01 Firmware · 4Clickshare Csm-1 Firmware · 4Transform N · 4Mirrorop Windows Sender · 2Wepresent Wipg-1000p Firmware · 2Clickshare Cx-20 · 1