7.2
CVE-2019-18828
- EPSS 0.1%
- Veröffentlicht 16.12.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:39
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Barco ≫ Clickshare Cs-100 Firmware Version < 1.9.0
Barco ≫ Clickshare Cse-200 Firmware Version < 1.9.0
Barco ≫ Clickshare Cse-200+ Firmware Version < 1.9.0
Barco ≫ Clickshare Cse-800 Firmware Version < 1.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.287 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-521 Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.