Vulnerability CVE-2020-28334


Published: 2020-11-24

Description:
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included in the firmware image. Exploiting CVE-2020-28329, CVE-2020-28330 and CVE-2020-28331 could potentially be used in a simple and automated exploit chain to go from unauthenticated remote attacker to root shell.

See advisories in our WLB2 database:
Topic
Author
Date
High
Barco wePresent Global Hardcoded Root SSH Password
Jim Becher
21.11.2020

Type:

CWE-798

 References:
http://packetstormsecurity.com/files/160163/Barco-wePresent-Global-Hardcoded-Root-SSH-Password.html
https://korelogic.com/Resources/Advisories/KL-001-2020-008.txt

Copyright 2024, cxsecurity.com

 

Back to Top