PT-2020-11972 · Amino Communications+1 · Amino Communications Aria6Xx Series+6

Published

2020-12-29

·

Updated

2021-01-14

·

CVE-2020-10206

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B (affected versions not specified)
Description The issue is related to the use of a hard-coded password in VNCserver, allowing local attackers to view and interact with the video output of the device. This could potentially lead to unauthorized access and control of the device's video output.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10206

Affected Products

Amino Communications Ak45X Series
Amino Communications Ak5Xx Series
Amino Communications Ak65X Series
Amino Communications Aria6Xx Series
Amino Communications Aria7/Ak7Xx Series
Amino Communications Kami7B
Vncserver