Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.
2019-12-16T17:15:12.080
2024-11-21T04:33:39.907
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | barco | clickshare_cs-100_firmware | < 1.9.0 | Yes |
Hardware | barco | clickshare_cs-100 | - | No |
Operating System | barco | clickshare_cse-200_firmware | < 1.9.0 | Yes |
Hardware | barco | clickshare_cse-200 | - | No |
Operating System | barco | clickshare_cse-200\+_firmware | < 1.9.0 | Yes |
Hardware | barco | clickshare_cse-200\+ | - | No |
Operating System | barco | clickshare_cse-800_firmware | < 1.9.0 | Yes |
Hardware | barco | clickshare_cse-800 | - | No |