Information Exposure Vulnerability in Barco ClickShare Buttons
CVE-2019-18833

5.9MEDIUM

Key Information:

Vendor

Barco

Vendor
CVE Published:
17 December 2019

What is CVE-2019-18833?

Barco ClickShare Button devices, specifically the R9861500D01 model versions prior to 1.9.0, expose sensitive information due to improper encryption key handling. When media content is shared between the ClickShare Button and its associated Base Unit, the encryption key is generated randomly for each session and transmitted over a TLS connection. If an attacker successfully executes a Man-in-the-Middle attack on the TLS channel, they can intercept the encryption key, resulting in unauthorized access to the streamed content.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-18833 : Information Exposure Vulnerability in Barco ClickShare Buttons