CVE Feed

    Dashboard / CVE / CVE-2020-28329

    CVE-2020-28329

    Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.

    Published:Nov 24, 2020
    Last Modified:Nov 21, 2024
    EPS:Nov 24, 2020
    EPSS Score:0.00706
    CVSS Score:9.8

    Affected Products

    Vendor
    Barco
    Product
    Wepresent Wipg-1600w
    Vendor
    Barco
    Product
    Wepresent Wipg-1600w Firmware

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High