First published: Thu Jan 12 2017(Updated: )
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to read /etc/shadow via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barco Clickshare CSC-1 | <=01.09.02.03 | |
ClickShare | ||
Barco ClickShare CSM-1 | <=01.06.01.04 | |
ClickShare | ||
Barco Clickshare CSE-200+ Firmware | <=01.03.01.05 | |
ClickShare |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3151 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2016-3151, upgrade the firmware of your Barco ClickShare devices to the latest versions: CSC-1 to 01.09.03 or later, CSM-1 to 01.06.02 or later, and CSE-200 to 01.03.02 or later.
CVE-2016-3151 affects Barco ClickShare CSC-1, CSM-1, and CSE-200 devices with specific firmware versions prior to the secure updates.
CVE-2016-3151 is a directory traversal vulnerability that allows unauthorized remote access to sensitive system files.
Attackers exploiting CVE-2016-3151 can read sensitive files, such as /etc/shadow, which can lead to unauthorized access to the system.