CVE-2020-3928: GeoVision Door Access Control Device - Hardcoded privileged password
Published Jun 12, 2020
·Updated
GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices.
Affected Software
10 affected components
Usavisionsys Geovision Gv-as210 Firmware<2.21
Usavisionsys Geovision Gv-as210
Usavisionsys Geovision Gv-as410 Firmware<2.21
Usavisionsys Geovision Gv-as410
Usavisionsys Geovision Gv-as810 Firmware<2.21
Usavisionsys Geovision Gv-as810
Usavisionsys Geovision Gv-as1010 Firmware<1.32
Usavisionsys Geovision Gv-as1010
Usavisionsys Geovision Gv-gf192x Firmware<1.10
Usavisionsys Geovision Gv-gf192x
Remediation
Information
Update to version 2.22 in GV-AS210
Update to version 2.22 in GV-AS410
Update to version 2.22 in GV-AS810
Update to version 1.22 in GV-GF192x
Update to version 1.33 in GV-AS1010
Event History
Jun 12, 2020
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-3928?
CVE-2020-3928 is a vulnerability in the GeoVision Door Access Control device family where a root password is hardcoded in all devices.
2
How severe is CVE-2020-3928?
CVE-2020-3928 has a severity rating of 9.8, which is considered critical.
3
Which devices are affected by CVE-2020-3928?
The GeoVision GV-AS210, GV-AS410, GV-AS810, GV-AS1010, and GV-GF192x devices are affected by CVE-2020-3928.
4
How can I fix CVE-2020-3928?
To fix CVE-2020-3928, it is recommended to contact the manufacturer for a firmware update or apply any available patches.
5
Where can I find more information about CVE-2020-3928?
More information about CVE-2020-3928 can be found at the following reference: [link](https://www.twcert.org.tw/tw/cp-132-3695-9e72d-1.html)