PT-2019-4694 · Barco+1 · Barco Clickshare Cs-100+4

Published

2019-12-16

·

Updated

2020-08-24

·

CVE-2019-18828

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Barco ClickShare CS-100 versions not specified Barco ClickShare CSE-200 versions not specified Barco ClickShare CSE-200+ versions not specified Barco ClickShare CSE-800 versions not specified Barco ClickShare Button R9861500D01 devices versions prior to 1.9.0
Description The issue is related to insufficient protection of registration data in the software of wireless systems. Exploitation of this issue may allow an attacker to elevate their privileges. The root account of the embedded Linux on the ClickShare Button uses a weak password, which is present for access via debug interfaces. These interfaces are not enabled by default on production devices.
Recommendations For Barco ClickShare CS-100, update to a version that addresses the issue, if available. For Barco ClickShare CSE-200, update to a version that addresses the issue, if available. For Barco ClickShare CSE-200+, update to a version that addresses the issue, if available. For Barco ClickShare CSE-800, update to a version that addresses the issue, if available. For Barco ClickShare Button R9861500D01 devices, update to version 1.9.0 or later. As a temporary workaround, consider disabling access to debug interfaces until a patch is available.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01070
CVE-2019-18828

Affected Products

Barco Clickshare Button R9861500D01
Barco Clickshare Cs-100
Barco Clickshare Cse-200
Barco Clickshare Cse-800
Linux