License File Upload Vulnerability in Barco Control Room Management Suite
CVE-2022-26973

5.3MEDIUM

Key Information:

Vendor

Barco

Vendor
CVE Published:
2 June 2022

What is CVE-2022-26973?

The Barco Control Room Management Suite, specifically versions of TransForm N prior to 3.14, is vulnerable due to an improperly secured license file upload mechanism. An attacker can manipulate the license file name to elicit error messages that inadvertently reveal sensitive internal directory path information, posing a risk for further attacks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-26973 : License File Upload Vulnerability in Barco Control Room Management Suite