Executive brief
Barco ClickShare CSC-1 wireless presentation systems contain a security flaw that allows the administrative root password to be recovered from the device's firmware. An attacker can download and analyze the firmware image to obtain these credentials, potentially leading to full unauthorized control over the presentation system. This could allow an adversary to intercept shared content or disrupt corporate meetings and operations.
Technical details
The Barco ClickShare CSC-1 presentation system suffers from an information disclosure vulnerability (CWE-200) due to the inclusion of sensitive credentials within its firmware images. Remote attackers can download the firmware and use extraction tools to recover the root password. This vulnerability is categorized as critical because it provides a path to full administrative access without requiring prior authentication. The issue is resolved in firmware version 01.09.03 and later.
Affected products
- Barco ClickShare CSC-1 firmware before 01.09.03
Timeline
- 2017-01-12: disclosed: NVD publication date