← Back

CVE-2020-17502

nvd nist
Published: Jan 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.

Affected (1)

Products: Barco: Transform N
1 product
Transform N
Configuration A
1 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Before 3.8
Running on/withPlatform Versions
Barco
Transform Ndn 210 Lite
All versions
Barco
Transform Ndn 210 Pro
All versions
Barco
Transform Ndn 211 Lite
All versions
Barco
Transform Ndn 211 Pro
All versions

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory

Timeline

No history available yet.