Записи Barco
40 опубликованных записей вендора barco.
Профиль для исследователя
- Попали в KEV
- 1 · 2,5 %
- С эксплойтом
- 1 · 2,5 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 1081 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
- CWE-798 Use of Hard-coded Credentials3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-345 Insufficient Verification of Data Authenticity2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
40 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-3929Готовый эксплойт | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Критическая9,8 | KEV | 99,0 % | 30 апр. 2019 г. |
41В плане | CVE-2016-3149Эксплойта нет | Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execubarco · clickshare csc-1 firmware | Критическая9,8 | — | 7,8 % | 12 янв. 2017 г. |
41В плане | CVE-2019-3930Эксплойта нет | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-121 | Критическая9,8 | — | 7,0 % | 30 апр. 2019 г. |
40В плане | CVE-2020-28334Эксплойта нет | Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2).barco · wepresent wipg-1600w firmware · CWE-798 | Критическая9,8 | — | 4,8 % | 24 нояб. 2020 г. |
40В плане | CVE-2019-18830Эксплойта нет | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection.barco · clickshare cs-100 firmware · CWE-78 | Критическая9,8 | — | 4,3 % | 16 дек. 2019 г. |
40В плане | CVE-2020-17500Эксплойта нет | Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4).barco · transform n · CWE-77 | Критическая9,8 | — | 3,9 % | 7 янв. 2021 г. |
40В плане | CVE-2020-28333Эксплойта нет | Barco wePresent WiPG-1600W devices allow Authentication Bypass.barco · wepresent wipg-1600w firmware · CWE-200 | Критическая9,8 | — | 3,2 % | 24 нояб. 2020 г. |
40В плане | CVE-2016-3152Эксплойта нет | Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extractinbarco · clickshare csc-1 firmware · CWE-200 | Критическая9,8 | — | 2,8 % | 12 янв. 2017 г. |
39Наблюдать | CVE-2020-28329Эксплойта нет | Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image.barco · wepresent wipg-1600w firmware · CWE-798 | Критическая9,8 | — | 1,6 % | 24 нояб. 2020 г. |
39Наблюдать | CVE-2020-28332Эксплойта нет | Barco wePresent WiPG-1600W devices download code without an Integrity Check.barco · wepresent wipg-1600w firmware · CWE-494 | Критическая9,8 | — | 1,1 % | 24 нояб. 2020 г. |
39Наблюдать | CVE-2019-18826Эксплойта нет | Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust.barco · clickshare cs-100 firmware · CWE-295 | Критическая9,8 | — | 0,7 % | 16 дек. 2019 г. |
36Наблюдать | CVE-2017-9377Эксплойта нет | A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0barco · clickshare csm-1 firmware · CWE-78 | Высокая8,8 | — | 4,3 % | 30 окт. 2017 г. |
35Наблюдать | CVE-2022-26233Proof of concept | Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to accbarco · control room management suite · CWE-22 | Высокая7,5 | — | 15,0 % | 3 апр. 2022 г. |
35Наблюдать | CVE-2021-38142Эксплойта нет | Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades.barco · mirrorop windows sender · CWE-319 | Высокая8,8 | — | 0,5 % | 7 сент. 2021 г. |
32Наблюдать | CVE-2019-18832Эксплойта нет | Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management.barco · clickshare button r9861500d01 firmware · CWE-327 | Высокая8,1 | — | 0,4 % | 17 дек. 2019 г. |
31Наблюдать | CVE-2016-3151Эксплойта нет | Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSbarco · clickshare csc-1 firmware · CWE-22 | Высокая7,5 | — | 4,3 % | 12 янв. 2017 г. |
31Наблюдать | CVE-2020-28331Эксплойта нет | Barco wePresent WiPG-1600W devices have Improper Access Control.barco · wepresent wipg-1600w firmware | Высокая7,5 | — | 1,7 % | 24 нояб. 2020 г. |
31Наблюдать | CVE-2021-35482Эксплойта нет | An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70.barco · mirrorop windows sender | Высокая7,8 | — | 0,4 % | 21 июл. 2021 г. |
31Наблюдать | CVE-2019-18829Эксплойта нет | Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check.barco · clickshare button r9861500d01 firmware · CWE-345 | Высокая7,8 | — | 0,3 % | 17 дек. 2019 г. |
30Наблюдать | CVE-2018-10943Эксплойта нет | An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3.barco · clickshare cse-200 firmware · CWE-20 | Высокая7,5 | — | 1,1 % | 10 июл. 2018 г. |
30Наблюдать | CVE-2022-26975Эксплойта нет | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.barco · control room management suite · CWE-287 | Высокая7,5 | — | 1,0 % | 2 июн. 2022 г. |
30Наблюдать | CVE-2019-18825Эксплойта нет | Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management.barco · clickshare cs-100 huddle firmware | Высокая7,5 | — | 0,6 % | 17 дек. 2019 г. |
29Наблюдать | CVE-2020-17502Эксплойта нет | Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4).barco · transform n · CWE-77 | Высокая7,2 | — | 2,8 % | 8 янв. 2021 г. |
29Наблюдать | CVE-2020-17503Эксплойта нет | The NDN-210 has a web administration panel which is made available over https.barco · transform n · CWE-77 | Высокая7,2 | — | 2,8 % | 8 янв. 2021 г. |
29Наблюдать | CVE-2020-17504Эксплойта нет | The NDN-210 has a web administration panel which is made available over https.barco · transform n · CWE-77 | Высокая7,2 | — | 2,8 % | 8 янв. 2021 г. |
- CVE-2019-392999Срочно
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %crestron · am-100 firmware30 апр. 2019 г.
- CVE-2016-314941В плане
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execu
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %barco · clickshare csc-1 firmware12 янв. 2017 г.
- CVE-2019-393041В плане
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %crestron · am-100 firmware30 апр. 2019 г.
- CVE-2020-2833440В плане
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2).
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %barco · wepresent wipg-1600w firmware24 нояб. 2020 г.
- CVE-2019-1883040В плане
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %barco · clickshare cs-100 firmware16 дек. 2019 г.
- CVE-2020-1750040В плане
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4).
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %barco · transform n7 янв. 2021 г.
- CVE-2020-2833340В плане
Barco wePresent WiPG-1600W devices allow Authentication Bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %barco · wepresent wipg-1600w firmware24 нояб. 2020 г.
- CVE-2016-315240В плане
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extractin
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %barco · clickshare csc-1 firmware12 янв. 2017 г.
- CVE-2020-2832939Наблюдать
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %barco · wepresent wipg-1600w firmware24 нояб. 2020 г.
- CVE-2020-2833239Наблюдать
Barco wePresent WiPG-1600W devices download code without an Integrity Check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %barco · wepresent wipg-1600w firmware24 нояб. 2020 г.
- CVE-2019-1882639Наблюдать
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %barco · clickshare cs-100 firmware16 дек. 2019 г.
- CVE-2017-937736Наблюдать
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %barco · clickshare csm-1 firmware30 окт. 2017 г.
- CVE-2022-2623335Наблюдать
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to acc
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %barco · control room management suite3 апр. 2022 г.
- CVE-2021-3814235Наблюдать
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %barco · mirrorop windows sender7 сент. 2021 г.
- CVE-2019-1883232Наблюдать
Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %barco · clickshare button r9861500d01 firmware17 дек. 2019 г.
- CVE-2016-315131Наблюдать
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CS
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %barco · clickshare csc-1 firmware12 янв. 2017 г.
- CVE-2020-2833131Наблюдать
Barco wePresent WiPG-1600W devices have Improper Access Control.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %barco · wepresent wipg-1600w firmware24 нояб. 2020 г.
- CVE-2021-3548231Наблюдать
An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %barco · mirrorop windows sender21 июл. 2021 г.
- CVE-2019-1882931Наблюдать
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %barco · clickshare button r9861500d01 firmware17 дек. 2019 г.
- CVE-2018-1094330Наблюдать
An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %barco · clickshare cse-200 firmware10 июл. 2018 г.
- CVE-2022-2697530Наблюдать
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %barco · control room management suite2 июн. 2022 г.
- CVE-2019-1882530Наблюдать
Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %barco · clickshare cs-100 huddle firmware17 дек. 2019 г.
- CVE-2020-1750229Наблюдать
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4).
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %barco · transform n8 янв. 2021 г.
- CVE-2020-1750329Наблюдать
The NDN-210 has a web administration panel which is made available over https.
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %barco · transform n8 янв. 2021 г.
- CVE-2020-1750429Наблюдать
The NDN-210 has a web administration panel which is made available over https.
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %barco · transform n8 янв. 2021 г.