Executive brief
Barco ClickShare is a wireless presentation system used in meeting rooms to share content from laptops to a central screen. A security flaw in how these devices handle wallpaper images allows an unauthorized person on the network to access sensitive system files. This could lead to the theft of administrative credentials, potentially allowing an attacker to take full control of the presentation hardware.
Technical details
A directory traversal vulnerability (CWE-22) exists in the wallpaper parsing functionality of multiple Barco ClickShare models. The flaw is located in the component responsible for processing wallpaper images, where insufficient input validation allows an attacker to use special characters (e.g., '../') to navigate outside the intended directory. A remote, unauthenticated attacker can exploit this over the network to read arbitrary files from the underlying Linux filesystem, specifically targeting /etc/shadow to obtain password hashes. The vulnerability is addressed in CSC-1 firmware 01.09.03, CSM-1 firmware 01.06.02, and CSE-200 firmware 01.03.02.
Affected products
- Barco ClickShare CSC-1 firmware before 01.09.03
- Barco ClickShare CSM-1 firmware before 01.06.02
- Barco ClickShare CSE-200 firmware before 01.03.02
Timeline
- 2016-03-10: disclosed: CVE reserved date
- 2017-01-12: advisory: NVD publication date