Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://labs.f-secure.com/advisories/multiple-vulnerabilities-in-barco-clickshare/ - Third Party Advisory | |
References | () https://www.barco.com/en/clickshare/firmware-update - Product | |
References | () https://www.barco.com/en/support/software/R33050069?majorVersion=01&minorVersion=09&patchVersion=01&buildVersion=007 - Product, Vendor Advisory | |
References | () https://www.barco.com/en/support/software/R33050070?majorVersion=01&minorVersion=09&patchVersion=01&buildVersion=007 - Product, Vendor Advisory | |
References | () https://www.barco.com/en/support/software/R33050095?majorVersion=01&minorVersion=09&patchVersion=01&buildVersion=007 - Product, Vendor Advisory | |
References | () https://www.barco.com/en/support/software/R33050125?majorVersion=01&minorVersion=09&patchVersion=01&buildVersion=007 - Product, Vendor Advisory |
Information
Published : 2019-12-16 17:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18830
Mitre link : CVE-2019-18830
CVE.ORG link : CVE-2019-18830
JSON object : View
Products Affected
barco
- clickshare_cse-800_firmware
- clickshare_cse-200
- clickshare_cse-200_firmware
- clickshare_cse-200\+
- clickshare_cse-200\+_firmware
- clickshare_cs-100
- clickshare_cs-100_firmware
- clickshare_cse-800
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')