Vulnerability CVE-2020-28329


Published: 2020-11-24

Description:
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Barco wePresent Hardcoded API Credentials
Jim Becher
21.11.2020
High
Barco wePresent Admin Credential Exposure
Jim Becher
21.11.2020

Type:

CWE-798

 References:
https://korelogic.com/Resources/Advisories/KL-001-2020-004.txt

Copyright 2020, cxsecurity.com

 

Back to Top