VYPR
Vendor

Barco

Products
21
CVEs
41
Across products
92
Status
Private

Products

21

Recent CVEs

41
View all 41 CVEs →
  • CVE-2019-3929CriKEVApr 30, 2019
    risk 0.87cvss 9.8epss 0.99

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware…

  • CVE-2020-17500CriJan 7, 2021
    risk 0.64cvss 9.8epss 0.04

    Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of 4). The NDN-210 has a web administration panel which is made available over https. The logon method is basic authentication. There is a command injection…

  • CVE-2020-28329CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.02

    Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8,…

  • CVE-2020-28334CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.05

    Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included in the firmware image. Exploiting CVE-2020-28329,…

  • CVE-2020-28333CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.03

    Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end…

  • CVE-2020-28332CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.01

    Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally signed firmware updates and is susceptible to processing…

  • CVE-2019-18830CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.04

    Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could…

  • CVE-2019-18826CriDec 16, 2019
    risk 0.64cvss 9.8epss 0.01

    Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate…

  • CVE-2019-3930CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.07

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware…

  • CVE-2016-3152CriJan 12, 2017
    risk 0.64cvss 9.8epss 0.03

    Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.

  • CVE-2016-3149CriJan 12, 2017
    risk 0.64cvss 9.8epss 0.08

    Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2017-9377HigOct 30, 2017
    risk 0.58cvss 8.8epss 0.04

    A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the vulnerable device.

  • CVE-2021-38142HigSep 7, 2021
    risk 0.57cvss 8.8epss 0.00

    Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker on the local network can achieve remote code execution on any computer that tries to update Windows Sender due to the fact that the upgrade mechanism is not…

  • CVE-2019-18832HigDec 17, 2019
    risk 0.53cvss 8.1epss 0.00

    Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Button implements encryption at rest which uses a one-time programmable (OTP) AES encryption key. This key is shared across all ClickShare Buttons of model R9861500D01.

  • CVE-2021-35482HigJul 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Barco MirrorOp Windows Sender before 2.5.4.70. An attacker in the local network is able to achieve Remote Code Execution (with user privileges of the local user) on any device that tries to connect to a WePresent presentation system.

  • CVE-2019-18829HigDec 17, 2019
    risk 0.51cvss 7.8epss 0.00

    Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed 'Clickshare_For_Windows.exe' binary on the ClickShare Button (R9861500D01) loads a number of DLL files dynamically without verifying their integrity.

  • CVE-2022-26233HigApr 3, 2022
    risk 0.50cvss 7.5epss 0.15

    Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

  • CVE-2024-53919HigDec 10, 2024
    risk 0.49cvss 7.6epss 0.00

    An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.

  • CVE-2022-26975HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.

  • CVE-2020-28331HigNov 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemon included in the firmware image. By default, the SSH daemon is disabled and does not start at system boot. The system…