|
223321
|
8.1 |
HIGH
Network
|
barco
|
clickshare_button_r9861500d01_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Button implements encryption at rest which uses a one-time programmable (OTP) AES encryp…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-18832
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223322
|
7.8 |
HIGH
Local
|
barco
|
clickshare_button_r9861500d01_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed 'Clickshare_For_Windows.exe' binary on the ClickShare Button (R9861500D01) load…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-18829
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223323
|
7.5 |
HIGH
Network
|
barco
|
clickshare_cs-100_huddle_firmware clickshare_cse-200_firmware
|
Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Base Unit implements encryption at rest using encryption key…
|
NVD-CWE-Other
|
CVE-2019-18825
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223324
|
6.6 |
MEDIUM
Physics
|
barco
|
clickshare_button_r9861500d01_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Button does not verify the integrity of the mutable content on the UBIFS partitio…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-18824
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223325
|
6.8 |
MEDIUM
Physics
|
dell
|
xps_7390_firmware
|
Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot module…
|
NVD-CWE-Other
|
CVE-2019-18579
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223326
|
5.3 |
MEDIUM
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-18831
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223327
|
9.8 |
CRITICAL
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is…
|
CWE-78
OS Command
|
CVE-2019-18830
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223328
|
6.8 |
MEDIUM
Physics
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on prod…
|
CWE-521
Weak Password Requirements
|
CVE-2019-18828
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223329
|
5.9 |
MEDIUM
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG access is possible when the system is running cod…
|
CWE-362 CWE-285
Race Condition Improper Authorization
|
CVE-2019-18827
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223330
|
9.8 |
CRITICAL
Network
|
barco
|
clickshare_cs-100_firmware clickshare_cse-200_firmware clickshare_cse-200\+_firmware clickshare_cse-800_firmware
|
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the Clic…
|
CWE-295
Improper Certificate Validation
|
CVE-2019-18826
|
2024-11-21 13:33 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|