Barco
barco
40 CVEs • 25 products
Products (25)
Click to collapseToggle
Products (25)
Click to collapse
CVEs (40)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS. |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS. |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS. |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication. |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS. |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal d...Show more |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS. |
1Barco 1Control Room Management Suite Nov 21, 2024 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This upload can be executed without authentication. |
1Barco 1Control Room Management Suite Nov 21, 2024 Apr 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\...Show more |
Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows S...Show more |
1Barco 1Mirrorop Windows Sender Nov 21, 2024 Jul 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to con...Show more |
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execu...Show more |
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execu...Show more |
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users...Show more |
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Nov 21, 2024 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative f...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Nov 21, 2024 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Nov 21, 2024 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the we...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Nov 21, 2024 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Nov 21, 2024 Nov 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API credentials (retrieved by exploiting CVE-2020-28329) can issue an authentic...Show more |