CVE-2017-9377: OS Command Injection
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-9377.
What is the severity of CVE-2017-9377?
The severity of CVE-2017-9377 is critical with a severity value of 8.8.
Which Barco ClickShare Base Unit devices are affected by CVE-2017-9377?
Barco ClickShare CSM-1 firmware versions up to 1.7.0.3 and CSC-1 firmware versions up to 1.10.0.10 are affected by CVE-2017-9377.
How can an attacker exploit CVE-2017-9377?
An attacker with access to the product's web API can exploit CVE-2017-9377 to completely compromise the vulnerable device.
Are there any references available for CVE-2017-9377?
Yes, you can find references for CVE-2017-9377 at these links: [http://www.securityfocus.com/bid/101617](http://www.securityfocus.com/bid/101617), [https://www.barco.com/en/Support/software/R33050037](https://www.barco.com/en/Support/software/R33050037), [https://www.barco.com/en/support/software/R33050020](https://www.barco.com/en/support/software/R33050020).