7.2

CVE-2019-18828

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BarcoClickshare Cs-100 Firmware Version < 1.9.0
   BarcoClickshare Cs-100 Version-
BarcoClickshare Cse-200 Firmware Version < 1.9.0
   BarcoClickshare Cse-200 Version-
BarcoClickshare Cse-200+ Firmware Version < 1.9.0
   BarcoClickshare Cse-200+ Version-
BarcoClickshare Cse-800 Firmware Version < 1.9.0
   BarcoClickshare Cse-800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.287
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-521 Weak Password Requirements

The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.