Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18833

Опубликовано: 17 дек. 2019
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a TLS connection. An attacker who is able to perform a Man-in-the-Middle attack between the TLS connection, is able to obtain the encryption key.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:barco:clickshare_button_r9861500d01_firmware:*:*:*:*:*:*:*:*
Версия до 1.9.0 (исключая)
cpe:2.3:h:barco:clickshare_button_r9861500d01:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00085
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-311

Связанные уязвимости

github
больше 3 лет назад

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a TLS connection. An attacker who is able to perform a Man-in-the-Middle attack between the TLS connection, is able to obtain the encryption key.

EPSS

Процентиль: 25%
0.00085
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-311