First published: Thu Jan 07 2021(Updated: )
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barco TransForm N | <3.8 | |
Barco TransForm NDN-210 Lite | ||
Barco Transform Ndn-210 Pro | ||
Barco Transform Ndn-211 Lite | ||
Barco Transform Ndn-211 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17500 is a command injection vulnerability in Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before version 3.8.
The severity of CVE-2020-17500 is critical with a CVSS score of 9.8.
CVE-2020-17500 allows command injection, which can lead to unauthorized code execution and potential compromise of the affected devices.
To fix CVE-2020-17500, users should update Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro to version 3.8 or later.
More information about CVE-2020-17500 can be found on the Barco support website: [https://www.barco.com/en/support/cms](https://www.barco.com/en/support/cms) and [https://www.barco.com/en/support/knowledge-base/kb11588](https://www.barco.com/en/support/knowledge-base/kb11588).