CVE-2019-18828

MEDIUM

Barco ClickShare Button R9861500D01 <1.9.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.

Scores

CVSS v3 6.8
EPSS 0.0008
EPSS Percentile 23.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-521
Status published
Products (4)
barco/clickshare_cs-100_firmware < 1.9.0
barco/clickshare_cse-200\+_firmware < 1.9.0
barco/clickshare_cse-200_firmware < 1.9.0
barco/clickshare_cse-800_firmware < 1.9.0
Published Dec 16, 2019
Tracked Since Feb 18, 2026