CVE-2017-9377

A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:barco:clickshare_csm-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_csm-1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:barco:clickshare_csc-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_csc-1:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-10-30 14:29

Updated : 2024-02-28 16:04


NVD link : CVE-2017-9377

Mitre link : CVE-2017-9377

CVE.ORG link : CVE-2017-9377


JSON object : View

Products Affected

barco

  • clickshare_csm-1_firmware
  • clickshare_csc-1_firmware
  • clickshare_csm-1
  • clickshare_csc-1
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')