CVE-2019-18828

CVSS v3 Score
6.8
Medium
CVSS v2 Score
7.2
High

Vulnerability Description

Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak password.

CVSS:6.7(Medium)

Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.

CVSS:7.0(High)

TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations ...

CVSS:6.5(Medium)

eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.

CVSS:6.5(Medium)

A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not ...

CVSS:6.5(Medium)

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an a...

CVSS:6.5(Medium)

Possible External Service Interaction attack in eDirectory has been discovered in OpenTextâ„¢ eDirectory. This impact all version before 9.2.6.0000.