Vulnerability Description
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate chain.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Barco | Clickshare Cs-100 Firmware | < 1.9.0 |
| Barco | Clickshare Cs-100 | - |
| Barco | Clickshare Cse-200 Firmware | < 1.9.0 |
| Barco | Clickshare Cse-200 | - |
| Barco | Clickshare Cse-200\+ Firmware | < 1.9.0 |
| Barco | Clickshare Cse-200\+ | - |
| Barco | Clickshare Cse-800 Firmware | < 1.9.0 |
| Barco | Clickshare Cse-800 | - |
Related Weaknesses (CWE)
References
- https://www.barco.com/en/clickshare/firmware-updateProductVendor Advisory
- https://www.barco.com/en/clickshare/firmware-updateProductVendor Advisory
FAQ
What is CVE-2019-18826?
CVE-2019-18826 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the Click...
How severe is CVE-2019-18826?
CVE-2019-18826 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-18826?
Check the references section above for vendor advisories and patch information. Affected products include: Barco Clickshare Cs-100 Firmware, Barco Clickshare Cs-100, Barco Clickshare Cse-200 Firmware, Barco Clickshare Cse-200, Barco Clickshare Cse-200\+ Firmware.