CVE-2019-18830

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:barco:clickshare_cs-100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_cs-100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:barco:clickshare_cse-200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_cse-200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:barco:clickshare_cse-200\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_cse-200\+:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:barco:clickshare_cse-800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:barco:clickshare_cse-800:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-16 17:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-18830

Mitre link : CVE-2019-18830

CVE.ORG link : CVE-2019-18830


JSON object : View

Products Affected

barco

  • clickshare_cs-100_firmware
  • clickshare_cse-200
  • clickshare_cse-800
  • clickshare_cse-800_firmware
  • clickshare_cse-200\+
  • clickshare_cs-100
  • clickshare_cse-200_firmware
  • clickshare_cse-200\+_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')