Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.
2019-12-16T17:15:12.080
2024-11-21T04:33:39.907
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | barco | clickshare_cs-100_firmware | < 1.9.0 | Yes |
| Hardware | barco | clickshare_cs-100 | - | No |
| Operating System | barco | clickshare_cse-200_firmware | < 1.9.0 | Yes |
| Hardware | barco | clickshare_cse-200 | - | No |
| Operating System | barco | clickshare_cse-200\+_firmware | < 1.9.0 | Yes |
| Hardware | barco | clickshare_cse-200\+ | - | No |
| Operating System | barco | clickshare_cse-800_firmware | < 1.9.0 | Yes |
| Hardware | barco | clickshare_cse-800 | - | No |