CVE-2019-3930
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to a stack buffer overflow in libAwgCgi.so's PARSERtoCHAR function. A remote, unauthenticated attacker can use this vulnerability to execute arbitrary code as root via a crafted request to the return.cgi endpoint.
Published:Apr 30, 2019
Last Modified:Nov 21, 2024
EPS:Apr 30, 2019
EPSS Score:0.15337
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Barco
Product
Wepresent Wipg-1000p
Barco
Wepresent Wipg-1000p
Vendor
Barco
Product
Wepresent Wipg-1000p Firmware
Barco
Wepresent Wipg-1000p Firmware
Vendor
Barco
Product
Wepresent Wipg-1600w
Barco
Wepresent Wipg-1600w
Vendor
Barco
Product
Wepresent Wipg-1600w Firmware
Barco
Wepresent Wipg-1600w Firmware
Vendor
Blackbox
Product
Hd Wireless Presentation System
Blackbox
Hd Wireless Presentation System
Vendor
Blackbox
Product
Hd Wireless Presentation System Firmware
Blackbox
Hd Wireless Presentation System Firmware
Vendor
Crestron
Product
Am-100
Crestron
Am-100
Vendor
Crestron
Product
Am-100 Firmware
Crestron
Am-100 Firmware
Vendor
Crestron
Product
Am-101
Crestron
Am-101
Vendor
Crestron
Product
Am-101 Firmware
Crestron
Am-101 Firmware
Vendor
Extron
Product
Sharelink 200
Extron
Sharelink 200
Vendor
Extron
Product
Sharelink 200 Firmware
Extron
Sharelink 200 Firmware
Vendor
Extron
Product
Sharelink 250
Extron
Sharelink 250
Vendor
Extron
Product
Sharelink 250 Firmware
Extron
Sharelink 250 Firmware
Vendor
Infocus
Product
Liteshow3
Infocus
Liteshow3
Vendor
Infocus
Product
Liteshow3 Firmware
Infocus
Liteshow3 Firmware
Vendor
Infocus
Product
Liteshow4
Infocus
Liteshow4
Vendor
Infocus
Product
Liteshow4 Firmware
Infocus
Liteshow4 Firmware
Vendor
Optoma
Product
Wps-pro
Optoma
Wps-pro
Vendor
Optoma
Product
Wps-pro Firmware
Optoma
Wps-pro Firmware
Vendor
Sharp
Product
Pn-l703wa
Sharp
Pn-l703wa
Vendor
Sharp
Product
Pn-l703wa Firmware
Sharp
Pn-l703wa Firmware
Vendor
Teqavit
Product
Wips710
Teqavit
Wips710
Vendor
Teqavit
Product
Wips710 Firmware
Teqavit
Wips710 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
