CVE-2019-18830

CRITICAL

Barco ClickShare Button R9861500D01 <1.9.0 - Command Injection

Title source: llm
STIX 2.1

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.

Scores

CVSS v3 9.8
EPSS 0.0434
EPSS Percentile 90.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (4)
barco/clickshare_cs-100_firmware < 1.9.0
barco/clickshare_cse-200\+_firmware < 1.9.0
barco/clickshare_cse-200_firmware < 1.9.0
barco/clickshare_cse-800_firmware < 1.9.0
Published Dec 16, 2019
Tracked Since Feb 18, 2026