Barco kayıtları
barco üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,5
- Silahlaştırılmış
- 1 · %2,5
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 1081 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
- CWE-798 Use of Hard-coded Credentials3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-345 Insufficient Verification of Data Authenticity2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-3929Silahlaştırılmış | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Kritik9,8 | KEV | %99,0 | 30 Nis 2019 |
41Planlayın | CVE-2016-3149İstismar yok | Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execubarco · clickshare csc-1 firmware | Kritik9,8 | — | %7,8 | 12 Oca 2017 |
41Planlayın | CVE-2019-3930İstismar yok | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-121 | Kritik9,8 | — | %7,0 | 30 Nis 2019 |
40Planlayın | CVE-2020-28334İstismar yok | Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2).barco · wepresent wipg-1600w firmware · CWE-798 | Kritik9,8 | — | %4,8 | 24 Kas 2020 |
40Planlayın | CVE-2019-18830İstismar yok | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection.barco · clickshare cs-100 firmware · CWE-78 | Kritik9,8 | — | %4,3 | 16 Ara 2019 |
40Planlayın | CVE-2020-17500İstismar yok | Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4).barco · transform n · CWE-77 | Kritik9,8 | — | %3,9 | 7 Oca 2021 |
40Planlayın | CVE-2020-28333İstismar yok | Barco wePresent WiPG-1600W devices allow Authentication Bypass.barco · wepresent wipg-1600w firmware · CWE-200 | Kritik9,8 | — | %3,2 | 24 Kas 2020 |
40Planlayın | CVE-2016-3152İstismar yok | Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extractinbarco · clickshare csc-1 firmware · CWE-200 | Kritik9,8 | — | %2,8 | 12 Oca 2017 |
39İzleyin | CVE-2020-28329İstismar yok | Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image.barco · wepresent wipg-1600w firmware · CWE-798 | Kritik9,8 | — | %1,6 | 24 Kas 2020 |
39İzleyin | CVE-2020-28332İstismar yok | Barco wePresent WiPG-1600W devices download code without an Integrity Check.barco · wepresent wipg-1600w firmware · CWE-494 | Kritik9,8 | — | %1,1 | 24 Kas 2020 |
39İzleyin | CVE-2019-18826İstismar yok | Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust.barco · clickshare cs-100 firmware · CWE-295 | Kritik9,8 | — | %0,7 | 16 Ara 2019 |
36İzleyin | CVE-2017-9377İstismar yok | A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0barco · clickshare csm-1 firmware · CWE-78 | Yüksek8,8 | — | %4,3 | 30 Eki 2017 |
35İzleyin | CVE-2022-26233Kavram kanıtı | Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to accbarco · control room management suite · CWE-22 | Yüksek7,5 | — | %15,0 | 3 Nis 2022 |
35İzleyin | CVE-2021-38142İstismar yok | Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades.barco · mirrorop windows sender · CWE-319 | Yüksek8,8 | — | %0,5 | 7 Eyl 2021 |
32İzleyin | CVE-2019-18832İstismar yok | Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management.barco · clickshare button r9861500d01 firmware · CWE-327 | Yüksek8,1 | — | %0,4 | 17 Ara 2019 |
31İzleyin | CVE-2016-3151İstismar yok | Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSbarco · clickshare csc-1 firmware · CWE-22 | Yüksek7,5 | — | %4,3 | 12 Oca 2017 |
31İzleyin | CVE-2020-28331İstismar yok | Barco wePresent WiPG-1600W devices have Improper Access Control.barco · wepresent wipg-1600w firmware | Yüksek7,5 | — | %1,7 | 24 Kas 2020 |
31İzleyin | CVE-2021-35482İstismar yok | An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70.barco · mirrorop windows sender | Yüksek7,8 | — | %0,4 | 21 Tem 2021 |
31İzleyin | CVE-2019-18829İstismar yok | Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check.barco · clickshare button r9861500d01 firmware · CWE-345 | Yüksek7,8 | — | %0,3 | 17 Ara 2019 |
30İzleyin | CVE-2018-10943İstismar yok | An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3.barco · clickshare cse-200 firmware · CWE-20 | Yüksek7,5 | — | %1,1 | 10 Tem 2018 |
30İzleyin | CVE-2022-26975İstismar yok | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.barco · control room management suite · CWE-287 | Yüksek7,5 | — | %1,0 | 2 Haz 2022 |
30İzleyin | CVE-2019-18825İstismar yok | Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management.barco · clickshare cs-100 huddle firmware | Yüksek7,5 | — | %0,6 | 17 Ara 2019 |
29İzleyin | CVE-2020-17502İstismar yok | Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4).barco · transform n · CWE-77 | Yüksek7,2 | — | %2,8 | 8 Oca 2021 |
29İzleyin | CVE-2020-17503İstismar yok | The NDN-210 has a web administration panel which is made available over https.barco · transform n · CWE-77 | Yüksek7,2 | — | %2,8 | 8 Oca 2021 |
29İzleyin | CVE-2020-17504İstismar yok | The NDN-210 has a web administration panel which is made available over https.barco · transform n · CWE-77 | Yüksek7,2 | — | %2,8 | 8 Oca 2021 |
- CVE-2019-392999Hemen
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99crestron · am-100 firmware30 Nis 2019
- CVE-2016-314941Planlayın
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execu
KritikCVSS 9,8İstismar yokEPSS %8barco · clickshare csc-1 firmware12 Oca 2017
- CVE-2019-393041Planlayın
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
KritikCVSS 9,8İstismar yokEPSS %7crestron · am-100 firmware30 Nis 2019
- CVE-2020-2833440Planlayın
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2).
KritikCVSS 9,8İstismar yokEPSS %5barco · wepresent wipg-1600w firmware24 Kas 2020
- CVE-2019-1883040Planlayın
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection.
KritikCVSS 9,8İstismar yokEPSS %4barco · clickshare cs-100 firmware16 Ara 2019
- CVE-2020-1750040Planlayın
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4).
KritikCVSS 9,8İstismar yokEPSS %4barco · transform n7 Oca 2021
- CVE-2020-2833340Planlayın
Barco wePresent WiPG-1600W devices allow Authentication Bypass.
KritikCVSS 9,8İstismar yokEPSS %3barco · wepresent wipg-1600w firmware24 Kas 2020
- CVE-2016-315240Planlayın
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extractin
KritikCVSS 9,8İstismar yokEPSS %3barco · clickshare csc-1 firmware12 Oca 2017
- CVE-2020-2832939İzleyin
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image.
KritikCVSS 9,8İstismar yokEPSS %2barco · wepresent wipg-1600w firmware24 Kas 2020
- CVE-2020-2833239İzleyin
Barco wePresent WiPG-1600W devices download code without an Integrity Check.
KritikCVSS 9,8İstismar yokEPSS %1barco · wepresent wipg-1600w firmware24 Kas 2020
- CVE-2019-1882639İzleyin
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust.
KritikCVSS 9,8İstismar yokEPSS %1barco · clickshare cs-100 firmware16 Ara 2019
- CVE-2017-937736İzleyin
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0
YüksekCVSS 8,8İstismar yokEPSS %4barco · clickshare csm-1 firmware30 Eki 2017
- CVE-2022-2623335İzleyin
Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to acc
YüksekCVSS 7,5Kavram kanıtıEPSS %15barco · control room management suite3 Nis 2022
- CVE-2021-3814235İzleyin
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades.
YüksekCVSS 8,8İstismar yokEPSS %0barco · mirrorop windows sender7 Eyl 2021
- CVE-2019-1883232İzleyin
Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management.
YüksekCVSS 8,1İstismar yokEPSS %0barco · clickshare button r9861500d01 firmware17 Ara 2019
- CVE-2016-315131İzleyin
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CS
YüksekCVSS 7,5İstismar yokEPSS %4barco · clickshare csc-1 firmware12 Oca 2017
- CVE-2020-2833131İzleyin
Barco wePresent WiPG-1600W devices have Improper Access Control.
YüksekCVSS 7,5İstismar yokEPSS %2barco · wepresent wipg-1600w firmware24 Kas 2020
- CVE-2021-3548231İzleyin
An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70.
YüksekCVSS 7,8İstismar yokEPSS %0barco · mirrorop windows sender21 Tem 2021
- CVE-2019-1882931İzleyin
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check.
YüksekCVSS 7,8İstismar yokEPSS %0barco · clickshare button r9861500d01 firmware17 Ara 2019
- CVE-2018-1094330İzleyin
An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3.
YüksekCVSS 7,5İstismar yokEPSS %1barco · clickshare cse-200 firmware10 Tem 2018
- CVE-2022-2697530İzleyin
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.
YüksekCVSS 7,5İstismar yokEPSS %1barco · control room management suite2 Haz 2022
- CVE-2019-1882530İzleyin
Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management.
YüksekCVSS 7,5İstismar yokEPSS %1barco · clickshare cs-100 huddle firmware17 Ara 2019
- CVE-2020-1750229İzleyin
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4).
YüksekCVSS 7,2İstismar yokEPSS %3barco · transform n8 Oca 2021
- CVE-2020-1750329İzleyin
The NDN-210 has a web administration panel which is made available over https.
YüksekCVSS 7,2İstismar yokEPSS %3barco · transform n8 Oca 2021
- CVE-2020-1750429İzleyin
The NDN-210 has a web administration panel which is made available over https.
YüksekCVSS 7,2İstismar yokEPSS %3barco · transform n8 Oca 2021