ID

VAR-201912-0680


CVE

CVE-2019-18829


TITLE

Barco ClickShare Button R9861500D01 Unreliable search path vulnerability in device

Trust: 0.8

sources: JVNDB: JVNDB-2019-013450

DESCRIPTION

Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed 'Clickshare_For_Windows.exe' binary on the ClickShare Button (R9861500D01) loads a number of DLL files dynamically without verifying their integrity. Barco ClickShare Button R9861500D01 The device contains an untrusted search path vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Attackers can use this vulnerability to inject arbitrary code

Trust: 2.16

sources: NVD: CVE-2019-18829 // JVNDB: JVNDB-2019-013450 // CNVD: CNVD-2020-22684

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-22684

AFFECTED PRODUCTS

vendor:barcomodel:clickshare button r9861500d01scope:ltversion:1.9.0

Trust: 1.4

vendor:barcomodel:clickshare button r9861500d01scope:ltversion:1.10.0.13

Trust: 1.0

sources: CNVD: CNVD-2020-22684 // JVNDB: JVNDB-2019-013450 // NVD: CVE-2019-18829

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-18829
value: HIGH

Trust: 1.0

NVD: CVE-2019-18829
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-22684
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201912-773
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-18829
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-22684
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-18829
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2019-18829
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-22684 // JVNDB: JVNDB-2019-013450 // CNNVD: CNNVD-201912-773 // NVD: CVE-2019-18829

PROBLEMTYPE DATA

problemtype:CWE-345

Trust: 1.0

problemtype:CWE-426

Trust: 0.8

sources: JVNDB: JVNDB-2019-013450 // NVD: CVE-2019-18829

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201912-773

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-201912-773

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-013450

PATCH

title:Update your ClickShare deviceurl:https://www.barco.com/en/clickshare/firmware-update

Trust: 0.8

title:Patch for Barco ClickShare Button R9861500D01 code issue vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/213719

Trust: 0.6

title:Barco ClickShare Button R9861500D01 Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=105918

Trust: 0.6

sources: CNVD: CNVD-2020-22684 // JVNDB: JVNDB-2019-013450 // CNNVD: CNNVD-201912-773

EXTERNAL IDS

db:NVDid:CVE-2019-18829

Trust: 3.0

db:JVNDBid:JVNDB-2019-013450

Trust: 0.8

db:CNVDid:CNVD-2020-22684

Trust: 0.6

db:CNNVDid:CNNVD-201912-773

Trust: 0.6

sources: CNVD: CNVD-2020-22684 // JVNDB: JVNDB-2019-013450 // CNNVD: CNNVD-201912-773 // NVD: CVE-2019-18829

REFERENCES

url:https://labs.f-secure.com/advisories/multiple-vulnerabilities-in-barco-clickshare/

Trust: 2.4

url:https://www.barco.com/en/clickshare/firmware-update

Trust: 2.2

url:https://www.barco.com/en/clickshare/support/software/r33050069?majorversion=01&minorversion=10&patchversion=00&buildversion=013

Trust: 1.6

url:https://www.barco.com/en/clickshare/support/software/r33050070?majorversion=01&minorversion=10&patchversion=00&buildversion=013

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-18829

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-18829

Trust: 0.8

sources: CNVD: CNVD-2020-22684 // JVNDB: JVNDB-2019-013450 // CNNVD: CNNVD-201912-773 // NVD: CVE-2019-18829

SOURCES

db:CNVDid:CNVD-2020-22684
db:JVNDBid:JVNDB-2019-013450
db:CNNVDid:CNNVD-201912-773
db:NVDid:CVE-2019-18829

LAST UPDATE DATE

2024-11-23T22:25:39.724000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-22684date:2020-04-13T00:00:00
db:JVNDBid:JVNDB-2019-013450date:2020-01-07T00:00:00
db:CNNVDid:CNNVD-201912-773date:2020-08-14T00:00:00
db:NVDid:CVE-2019-18829date:2024-11-21T04:33:39.760

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-22684date:2020-04-13T00:00:00
db:JVNDBid:JVNDB-2019-013450date:2020-01-07T00:00:00
db:CNNVDid:CNNVD-201912-773date:2019-12-17T00:00:00
db:NVDid:CVE-2019-18829date:2019-12-17T14:15:17.903