CVE-2019-18826

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
16/12/2019
Last modified:
27/12/2019

Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The embedded 'dongle_bridge' program used to expose the functionalities of the ClickShare Button to a USB host, does not properly validate the whole certificate chain.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:barco:clickshare_cs-100_firmware:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:h:barco:clickshare_cs-100:-:*:*:*:*:*:*:*
cpe:2.3:o:barco:clickshare_cse-200_firmware:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:h:barco:clickshare_cse-200:-:*:*:*:*:*:*:*
cpe:2.3:o:barco:clickshare_cse-200\+_firmware:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:h:barco:clickshare_cse-200\+:-:*:*:*:*:*:*:*
cpe:2.3:o:barco:clickshare_cse-800_firmware:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:h:barco:clickshare_cse-800:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools