peter bassill · operator
$ cve CVE-2019-18830 JSON

CVE-2019-18830

9.8
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, is vulnerable to OS command injection vulnerabilities. These vulnerabilities could lead to code execution on the ClickShare Button with the privileges of the user 'nobody'.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.34% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-12-16
Last modified2026-06-17

Affected (8)

VendorProduct
barcoclickshare cs-100
barcoclickshare cs-100 firmware
barcoclickshare cse-200
barcoclickshare cse-200 firmware
barcoclickshare cse-200\+
barcoclickshare cse-200\+ firmware
barcoclickshare cse-800
barcoclickshare cse-800 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD