Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-18827


On Barco ClickShare Button R9861500D01 devices (before firmware version 1.9.0) JTAG access is disabled after ROM code execution. This means that JTAG access is possible when the system is running code from ROM before handing control over to embedded firmware.


Published

2019-12-16T17:15:11.957

Last Modified

2024-11-21T04:33:39.447

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-285
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System barco clickshare_cs-100_firmware < 1.9.0 Yes
Hardware barco clickshare_cs-100 - No
Operating System barco clickshare_cse-200_firmware < 1.9.0 Yes
Hardware barco clickshare_cse-200 - No
Operating System barco clickshare_cse-200\+_firmware < 1.9.0 Yes
Hardware barco clickshare_cse-200\+ - No
Operating System barco clickshare_cse-800_firmware < 1.9.0 Yes
Hardware barco clickshare_cse-800 - No

References