Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Information
Published : 2019-12-16 09:15
Updated : 2019-12-23 10:11
NVD link : CVE-2019-18830
Mitre link : CVE-2019-18830
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
barco
- clickshare_cse-800_firmware
- clickshare_cs-100_firmware
- clickshare_cse-800
- clickshare_cs-100
- clickshare_cse-200\+
- clickshare_cse-200\+_firmware
- clickshare_cse-200_firmware
- clickshare_cse-200