7.2
CVE-2019-18828
- EPSS 0.1%
- Published 16.12.2019 17:15:12
- Last modified 21.11.2024 04:33:39
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.
Data is provided by the National Vulnerability Database (NVD)
Barco ≫ Clickshare Cs-100 Firmware Version < 1.9.0
Barco ≫ Clickshare Cse-200 Firmware Version < 1.9.0
Barco ≫ Clickshare Cse-200+ Firmware Version < 1.9.0
Barco ≫ Clickshare Cse-800 Firmware Version < 1.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.287 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-521 Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.