Unprotected Credential Transmission in Barco wePresent WiPG-1600W Devices
CVE-2020-28330

6.5MEDIUM

Key Information:

Vendor

Barco

Vendor
CVE Published:
24 November 2020

What is CVE-2020-28330?

The Barco wePresent WiPG-1600W devices are vulnerable to credential exposure due to unprotected transport mechanisms. Specifically, an attacker who has obtained hardcoded API credentials—potentially retrieved by exploiting related vulnerabilities—can execute authenticated queries. This could allow the attacker to access sensitive information, such as the admin password for the web-based user interface. The issue predominantly affects systems running version 2.5.1.8, highlighting serious security implications for users relying on these devices for wireless presentation.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.