CVE-2020-17500: Command Injection
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection issue that will result in unauthenticated remote code execution in the username and password fields of the logon prompt. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-17500?
CVE-2020-17500 is a command injection vulnerability in Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before version 3.8.
What is the severity of CVE-2020-17500?
The severity of CVE-2020-17500 is critical with a CVSS score of 9.8.
How does CVE-2020-17500 impact Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro?
CVE-2020-17500 allows command injection, which can lead to unauthorized code execution and potential compromise of the affected devices.
How can I fix CVE-2020-17500?
To fix CVE-2020-17500, users should update Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro to version 3.8 or later.
Where can I find more information about CVE-2020-17500?
More information about CVE-2020-17500 can be found on the Barco support website: [https://www.barco.com/en/support/cms](https://www.barco.com/en/support/cms) and [https://www.barco.com/en/support/knowledge-base/kb11588](https://www.barco.com/en/support/knowledge-base/kb11588).