Barco Clickshare Csc-1 Firmware vulnerabilities
6 known vulnerabilities affecting barco/clickshare_csc-1_firmware.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2016-3149P2CRITICALCVSS 9.8≤ 01.09.02.032017-01-12
CVE-2016-3149 [CRITICAL] CVE-2016-3149: Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2017-9377P2HIGHCVSS 8.8fixed in 1.10.0.102017-10-30
CVE-2017-9377 [HIGH] CWE-78 CVE-2017-9377: A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.
nvd
CVE-2016-3152P3CRITICALCVSS 9.8≤ 01.09.02.032017-01-12
CVE-2016-3152 [CRITICAL] CWE-200 CVE-2016-3152: Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the ro
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.
nvd
CVE-2016-3151P3HIGHCVSS 7.5≤ 01.09.02.032017-01-12
CVE-2016-3151 [HIGH] CWE-22 CVE-2016-3151: Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 d
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to read /etc/shadow via unspecified vectors.
nvd
CVE-2016-3150P4MEDIUMCVSS 6.1≤ 01.09.05.022017-01-12
CVE-2016-3150 [MEDIUM] CWE-79 CVE-2016-3150: Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1
Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2017-12460P4MEDIUMCVSS 5.4fixed in 1.10.0.102017-10-30
CVE-2017-12460 [MEDIUM] CWE-79 CVE-2017-12460: An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as background on the ClickShare product. By uploading a wallpaper with a specially crafted name, an HTML injection can be triggered as special characters ar
nvd