CVE-2020-17502: Command Injection
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users of the administration panel to perform authenticated remote code execution. An issue exists in splitcardcmd.php in which the http parameters xmodules, ymodules and savelocking are not properly handled. The NDN-210 is part of Barco TransForm N solution and includes the patch from TransForm N version 3.8 onwards.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-17502.
What is the severity of CVE-2020-17502?
The severity of CVE-2020-17502 is high with a CVSS score of 7.2.
What is affected by CVE-2020-17502?
Barco TransForm N versions up to and including 3.8 are affected by CVE-2020-17502.
How can authenticated users perform remote code execution?
Authenticated users of the Barco TransForm N web administration panel can perform authenticated remote code execution by exploiting the command injection vulnerability.
Where can I find support and additional information about Barco TransForm N?
You can find support and additional information about Barco TransForm N on Barco's support website: [https://www.barco.com/en/support/cms](https://www.barco.com/en/support/cms)