vendor:
OEM Presentation Platform
by:
Jacob Baines
9.8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: OEM Presentation Platform
Affected Version From: 1.6.0.2
Affected Version To: 2.4.1.19
Patch Exists: YES
Related CWE: CVE-2019-3929
CPE: h:barco:awind_oem_presentation_platform
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Crestron AM-100, Crestron AM-101, Barco wePresent WiPG-1000P, Barco wePresent WiPG-1600W, Extron ShareLink 200/250, Teq AV IT WIPS710, InFocus LiteShow3, InFocus LiteShow4, Optoma WPS-Pro, Blackbox HD WPS, SHARP PN-L703WA
2019
Barco/AWIND OEM Presentation Platform Unauthenticated Remote Command Injection
A vulnerability in Barco/AWIND OEM Presentation Platform allows an unauthenticated attacker to execute arbitrary commands on the target device. This vulnerability is due to improper input validation of user-supplied data. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the vulnerable device. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the target device.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update their devices to the latest version.