CVE-2017-9377
Last modified
CVE-2017-9377 is a vulnerability of currently unknown severity. A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.. EPSS estimates a 4.35% chance of exploitation in the next 30 days.
Description
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Barco | Clickshare Csm-1 Firmware | < 1.7.0.3 |
| Barco | Clickshare Csc-1 Firmware | < 1.10.0.10 |
References
- http://www.securityfocus.com/bid/101617Third Party Advisory, VDB Entry
- https://www.barco.com/en/Support/software/R33050037Patch, Release Notes
- https://www.barco.com/en/support/software/R33050020Patch, Release Notes
- https://www.contextis.com/resources/advisories/cve-2017-9377Third Party Advisory
- http://www.securityfocus.com/bid/101617Third Party Advisory, VDB Entry
- https://www.barco.com/en/Support/software/R33050037Patch, Release Notes
- https://www.barco.com/en/support/software/R33050020Patch, Release Notes
- https://www.contextis.com/resources/advisories/cve-2017-9377Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9377?
How severe is CVE-2017-9377?
How do I fix CVE-2017-9377?
Are you affected by CVE-2017-9377?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
