CVE-2020-28329: Critical severity barco wepresent wipg-1600w firmware vulnerability
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28329?
CVE-2020-28329 is a vulnerability in the Barco wePresent WiPG-1600W firmware that includes a hardcoded API account and password.
How can a malicious actor exploit CVE-2020-28329?
A malicious actor can exploit CVE-2020-28329 by using the hardcoded API account and password to access authenticated, administrative functions in the API.
Which versions of Barco wePresent WiPG-1600W firmware are affected by CVE-2020-28329?
The affected versions of Barco wePresent WiPG-1600W firmware are 2.5.1.8, 2.5.0.25, 2.5.0.24, and 2.4.1.19.
What is the severity of CVE-2020-28329?
CVE-2020-28329 has a severity rating of 9.8 (critical).
Where can I find more information about CVE-2020-28329?
You can find more information about CVE-2020-28329 at the following reference link: [https://korelogic.com/Resources/Advisories/KL-001-2020-004.txt]