01/15/2019 - Tenable contacts InFocus support and asks for a security contact.
01/15/2019 - InFocus indicates support is the correct point of contact.
01/15/2019 - Tenable contacts Teq AVIT support and asks for a security contact.
01/15/2019 - Tenable receives an automated response from Teq AVIT.
01/15/2019 - Tenable extracts
[email protected] from Crestron's reporting PDF. Asks Crestron contact if that is correct.
01/15/2019 - Crestron confirms.
01/16/2019 - Tenable discloses to Crestron, Barco, InFocus, and Teq AVIT via email. Tenable attempts to disclose to Extron via their web reporting mechanism but that failed... awaiting instructions from Extron. Coordinated disclosure for all companies is
01/16/2019 - Automated acknowledgement received from InFocus.
01/16/2019 - Extron representative contacts Tenable and asks if we need technical help with their products.
01/16/2019 - Tenable replies to Extron that we'd like to report security issues in one of their products.
01/16/2019 - Extron says an engineer will reach out to Tenable.
01/16/2019 - InFocus acknowledges receipt and forwards to development.
01/17/2019 - Tenable receives undeliverable messages for Crestron's stated disclosure email address.
01/17/2019 - Tenable discloses to a known Crestron contact.
01/17/2019 - Barco PSIRT acknowledges receipt. Forwarded to engineering.
01/23/2019 - Tenable reminds Extron that an engineer is supposed to contact them.
01/23/2019 - Tenable asks Teq AVIT to acknowledge the disclosure.
01/25/2019 - Infocus acknowledges the vulns and indicates they will fix them when resources become available.
01/25/2019 - Tenable acknowledges Infocus and reminds them of the April 17th deadline.
01/31/2019 - Tenable asks Crestron to acknowledge the disclosure.
02/03/2019 - Crestron indicates the vulnerabilities were passed to the OEM.
02/04/2019 - Tenable asks Crestron if the OEM is Barco? Tenable also asks about some differences in patch levels they'd noticed.
02/21/2019 - Crestron says 8 of the vulnerabilities are "already known and have fixes coming"
02/21/2019 - Tenable asks if they are publicly known or internally known.
02/22/2019 - Crestron says internally.
02/26/2019 - Tenable indicates their discovery is considered "independent discovery" and that their disclosure policy will still apply.
02/26/2019 - Crestron agrees.
02/27/2019 - InFocus provides Tenable fixes to look at.
02/27/2019 - Tenable indicates to InFocus that these fixes are incorrect.
02/27/2019 - InFocus says they will go back to the devs.
03/07/2019 - Barco release 2.3.1.16 for the WiPG-1000.
03/07/2019 - Tenable tells Barco they should have waited for the April 17th coordination date.
03/07/2019 - Barco indicates this worked best for their release policy.
03/15/2019 - Crestron asks about communication with other vendors and concerns about OEM delivery.
03/15/2019 - Tenable indicates they've been in contact with a few vendors and that Barco has already released a patch.
03/19/2019 - Tenable reminds Extron that we are still waiting on an engineer to contact us.
03/19/2019 - Tenable again asks Teq AV IT to acknowledge the disclosure.
03/19/2019 - Extron attempts to call Tenable.
03/19/2019 - Tenable indicates written communication is the preferred medium. Tenable reiterates that they want to disclose vulnerabilities.
03/19/2019 - Extron says to forward information to them.
03/19/2019 - Tenable discloses to Extron.
03/19/2019 - Extron acknowledges.
03/26/2019 - Tenable asks Barco about issues Crestron reported with the OEM.
03/26/2019 - Tenable asks Crestron if they've had any follow up from the OEM.
03/26/2019 - Crestron says yes and they expect patches by April 5.
03/26/2019 - Tenable thanks Crestron.
03/29/2019 - Extron asks if Tenable is in contact with the OEM. Also, indicates that they won't have patches until May 20.
03/29/2019 - Tenable acknowledges that they've been in communication with the OEM since January 16. Tenable also indicates that May 20th is outside the 90 day disclosure window.
03/29/2019 - Tenable asks Barco to verify a list of OEM partners.
03/29/2019 - Extron asks if they can quote Tenable in communication to OEM.
03/30/2019 - Tenable says that is fine.
04/01/2019 - Barco says they are working to identify all affected ODM partners. Asks Tenable for a full list of vulns.
04/01/2019 - Tenable indicates Barco should have a full list already.
04/02/2019 - Tenable again asks Barco about their OEM partners and who they are in contact with. Tenable also informs Barco of the assigned CVE.
04/03/2019 - Tenable provides 2 week notice and CVE assignment to Crestron, Infocus, and Extron.
04/03/2019 - Extron indicates they need until April 30th to release patches.
04/03/2019 - Tenable points out the 2 week grace period in their disclosure policy.
04/03/2019 - Extron confirms patches will be released on April 30th. Ask Tenable about CVE assignment.
04/04/2019 - Tenable acknowledges April 30th as the new coordinated disclosure date. Tenable also explains the odd circumstances around CVE-2017-16709.
04/04/2019 - Tenable informs Barco, InFocus, and Crestron of the new disclosure date due to Extron invoking the 2 week grace period.
04/04/2019 - InFocus acknowledges new date.
04/04/2019 - Barco says they will get back to Tenable on OEM question by next Monday.
04/08/2019 - Barco states, "We can only provide information for Barco products and cannot provide any information about ODM partners as this is company restricted information."
04/08/2019 - Tenable acknowledges the limitation in communication and indicates they will reach out to company SHARP, Blackbox, and Optoma to ensure they have an opportunity to work with Barco.
04/08/2019 - Tenable informs SHARP via webform. Tenable couldn't find any other contact method.
04/08/2019 - Tenable informs Blackbox via email.
04/08/2019 - Black box assigns reference 52085.
04/08/2019 - Tenable informs Optoma via webform. Tenable couldn't find any other contact method.
04/08/2019 - Optoma assigns case ID 00331523
04/08/2019 - Tenable receives an undeliverable mail notification from SHARP... Tenable notes we filled out a webform.
04/08/2019 - Optoma states, "The WPS-Pro is not made by Barco"
04/08/2019 - Black box states, "the last firmware version we had from Awind was 1.0.0.5" and also notes that they no longer offer the product.
04/24/2019 - Tenable reminds Crestron, Barco, InFocus, and Extron of impending publication.
04/24/2019 - Extron acknowledges Tenable's reminder and indicates they'll be ready.
04/25/2019 - Crestron acknowledges Tenable's reminder and indicates they might not make the patch date.
04/29/2019 - Barco informs release of improved patches in the WiPG-1000P and WiPG-1600W.
04/29/2019 - Tenable thanks Barco.