Directory Traversal Vulnerability in Barco Control Room Management Suite
CVE-2022-26233

7.5HIGH

Key Information:

Vendor

Barco

Vendor
CVE Published:
3 April 2022

What is CVE-2022-26233?

The Barco Control Room Management Suite version 2.9 Build 0275 is susceptible to a directory traversal vulnerability. This security flaw enables attackers to craft requests that exploit the file path, allowing unauthorized access to sensitive components and information stored on the system. Attackers can initiate access through a specific format in the request, beginning with the 'GET /....' substring, effectively bypassing normal directory restrictions. Promptly addressing this issue is essential to safeguard data integrity and security.

References

EPSS Score

85% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-26233 : Directory Traversal Vulnerability in Barco Control Room Management Suite