First published: Tue Dec 17 2019(Updated: )
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a TLS connection. An attacker who is able to perform a Man-in-the-Middle attack between the TLS connection, is able to obtain the encryption key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Barco Clickshare Button R9861500d01 Firmware | <1.9.0 | |
Barco ClickShare Button R9861500D01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18833 is a vulnerability that allows information exposure in Barco ClickShare Button R9861500D01 devices before version 1.9.0.
CVE-2019-18833 allows an attacker to access the encryption key of the media content shared between a ClickShare Button and a ClickShare Base Unit.
The severity of CVE-2019-18833 is medium, with a CVSS score of 5.9.
To fix CVE-2019-18833, update your Barco ClickShare Button R9861500D01 device firmware to version 1.9.0 or later.
You can find more information about CVE-2019-18833 in the F-Secure advisory and Barco ClickShare firmware update.