CVE-2020-28334: Critical severity barco wepresent wipg-1600w firmware vulnerability
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included in the firmware image. Exploiting CVE-2020-28329, CVE-2020-28330 and CVE-2020-28331 could potentially be used in a simple and automated exploit chain to go from unauthenticated remote attacker to root shell.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28334?
CVE-2020-28334 is a vulnerability that affects Barco wePresent WiPG-1600W devices and allows the use of hard-coded credentials.
What is the severity of CVE-2020-28334?
CVE-2020-28334 has a severity rating of 9.8, which is considered critical.
Which versions of Barco wePresent WiPG-1600W firmware are affected by CVE-2020-28334?
The affected versions of Barco wePresent WiPG-1600W firmware are 2.5.1.8, 2.5.0.25, 2.5.0.24, and 2.4.1.19.
What is the impact of exploiting CVE-2020-28334?
Exploiting CVE-2020-28334 allows unauthorized access to affected Barco wePresent WiPG-1600W devices.
How can I mitigate the vulnerability CVE-2020-28334?
To mitigate the vulnerability, it is recommended to update the Barco wePresent WiPG-1600W firmware to a non-vulnerable version.