SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-18828

The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.

MEDIUM 6.8EPSS 0.39%

Does this matter?

Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.39% probability · 33th percentile
CISA KEV
Not listed
Weakness
CWE-521
Affected
barco/clickshare cs-100 firmware · barco/clickshare cse-200 firmware · barco/clickshare cse-200\+ firmware · barco/clickshare cse-800 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.