Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r54x-g9vf-56fv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.

Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.

EPSS

Процентиль: 72%
0.00706
Низкий

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative functions in the API. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19.

EPSS

Процентиль: 72%
0.00706
Низкий

Дефекты

CWE-798