PT-2019-15688 · Barco · Clickshare Button

Published

2019-12-17

·

Updated

2021-07-21

·

CVE-2019-18832

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Barco ClickShare Button R9861500D01 versions prior to 1.9.0
Description The issue concerns incorrect Credentials Management in the affected devices. Specifically, the ClickShare Button implements encryption at rest using a one-time programmable (OTP) AES encryption key, which is shared across all devices of the model R9861500D01.
Recommendations For versions prior to 1.9.0, update to version 1.9.0 or later to resolve the issue.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18832

Affected Products

Clickshare Button