Security Flaw in Barco ClickShare Button - R9861500D01
CVE-2019-18832

8.1HIGH

Key Information:

Vendor

Barco

Vendor
CVE Published:
17 December 2019

What is CVE-2019-18832?

The Barco ClickShare Button R9861500D01 devices, specifically those operating on versions prior to 1.9.0, exhibit a serious flaw in their credentials management. The implementation of encryption at rest relies on a one-time programmable (OTP) AES encryption key that is shared across all devices of the same model. This design exposes a potential risk, as the exposure of this key could lead to unauthorized access and manipulation of sensitive data across multiple devices.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.