Podatność CVE-2020-28329


Publikacja: 2020-11-24

Opis:
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.

W naszej bazie, znaleźliśmy następujące noty dla tego CVE:
Tytuł
Autor
Data
Med.
Barco wePresent Hardcoded API Credentials
Jim Becher
21.11.2020
High
Barco wePresent Admin Credential Exposure
Jim Becher
21.11.2020

Typ:

CWE-798

 Referencje:
https://korelogic.com/Resources/Advisories/KL-001-2020-004.txt

Copyright 2024, cxsecurity.com

 

Back to Top