CVE-2020-17503
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that will allow authenticated users to the administration panel to perform authenticated remote code execution. An issue exists in split_card_cmd.php in which the http parameter "locking" is not properly handled. The NDN-210 is part of Barco TransForm N solution and this vulnerability is patched from TransForm N version 3.8 onwards.
El NDN-210 presenta un panel de administración web que está disponible a través de https. Se presenta un problema de inyección de comando que permitirá a usuarios autenticados en el panel de administración llevar a cabo una ejecución de código remota autenticada. Se presenta un problema en el archivo split_card_cmd.php en el que el parámetro http "locking" no es manejado apropiadamente. El NDN-210 es parte de la solución de Barco TransForm N y esta vulnerabilidad está parcheada a partir de TransForm N versión 3.8 en adelante
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-12 CVE Reserved
- 2021-01-08 CVE Published
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.barco.com/en/support/cms | 2021-01-14 | |
https://www.barco.com/en/support/knowledge-base/kb11589 | 2021-01-14 | |
https://www.barco.com/en/support/transform-n-management-server | 2021-01-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barco Search vendor "Barco" | Transform N Search vendor "Barco" for product "Transform N" | < 3.8 Search vendor "Barco" for product "Transform N" and version " < 3.8" | - |
Affected
| in | Barco Search vendor "Barco" | Transform Ndn-210 Lite Search vendor "Barco" for product "Transform Ndn-210 Lite" | - | - |
Safe
|
Barco Search vendor "Barco" | Transform N Search vendor "Barco" for product "Transform N" | < 3.8 Search vendor "Barco" for product "Transform N" and version " < 3.8" | - |
Affected
| in | Barco Search vendor "Barco" | Transform Ndn-210 Pro Search vendor "Barco" for product "Transform Ndn-210 Pro" | - | - |
Safe
|
Barco Search vendor "Barco" | Transform N Search vendor "Barco" for product "Transform N" | < 3.8 Search vendor "Barco" for product "Transform N" and version " < 3.8" | - |
Affected
| in | Barco Search vendor "Barco" | Transform Ndn-211 Lite Search vendor "Barco" for product "Transform Ndn-211 Lite" | - | - |
Safe
|
Barco Search vendor "Barco" | Transform N Search vendor "Barco" for product "Transform N" | < 3.8 Search vendor "Barco" for product "Transform N" and version " < 3.8" | - |
Affected
| in | Barco Search vendor "Barco" | Transform Ndn-211 Pro Search vendor "Barco" for product "Transform Ndn-211 Pro" | - | - |
Safe
|