CVE-2019-18833
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a TLS connection. An attacker who is able to perform a Man-in-the-Middle attack between the TLS connection, is able to obtain the encryption key.
Los dispositivos Barco ClickShare Button R9861500D01 versiones anteriores a la versión 1.9.0, permiten una exposición de información (problema 2 de 2). La clave de cifrado del contenido multimedia que se compartió entre un ClickShare Button y un ClickShare Base Unit es generada aleatoriamente para cada nueva sesión y se comunicó por medio de una conexión TLS. Un atacante que puede realizar un ataque de tipo Man-in-the-Middle entre la conexión TLS, puede obtener la clave de cifrado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-07 CVE Reserved
- 2019-12-17 CVE Published
- 2023-04-21 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-311: Missing Encryption of Sensitive Data
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://labs.f-secure.com/advisories/multiple-vulnerabilities-in-barco-clickshare | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.barco.com/en/clickshare/firmware-update | 2019-12-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barco Search vendor "Barco" | Clickshare Button R9861500d01 Firmware Search vendor "Barco" for product "Clickshare Button R9861500d01 Firmware" | < 1.9.0 Search vendor "Barco" for product "Clickshare Button R9861500d01 Firmware" and version " < 1.9.0" | - |
Affected
| in | Barco Search vendor "Barco" | Clickshare Button R9861500d01 Search vendor "Barco" for product "Clickshare Button R9861500d01" | - | - |
Safe
|