CVE-2022-26973: Medium severity barco control room management suite vulnerability
Published Jun 1, 2022
·Updated
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the returned error message exposes internal directory path details.
Affected Software
1 affected component
Barco Control Room Management Suite<3.14.1
Event History
Jun 1, 2022
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-26973.
2
What is the severity of CVE-2022-26973?
The severity of CVE-2022-26973 is medium with a score of 5.3.
3
What software is affected by CVE-2022-26973?
Barco Control Room Management Suite web application, which is part of TransForm N before version 3.14.1, is affected by CVE-2022-26973.
4
What is the issue with Barco Control Room Management Suite?
Barco Control Room Management Suite web application is exposing a license file upload mechanism that exposes internal directory path details when the license file name is tweaked.
5
Are there any fixes or patches available for CVE-2022-26973?
Please refer to the Barco support website for available fixes or patches for CVE-2022-26973.