Record summary

CVE-2022-26233 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHBarco Control Room Management Suite <=2.9 Build 0275 - Local File InclusionCVSS 7.5

Barco Control Room Management through Suite 2.9 Build 0275 is vulnerable to local file inclusion that could allow attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

Impact

An attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.

Remediation

Upgrade Barco Control Room Management Suite to a version higher than 2.9 Build 0275 to mitigate the vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2022barcolfiseclistspacketstormvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:barco:control_room_management_suite:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3