SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-18830

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection.

CRITICAL 9.8EPSS 4.34%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.34% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
barco/clickshare cs-100 firmware · barco/clickshare cse-200 firmware · barco/clickshare cse-200\+ firmware · barco/clickshare cse-800 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.