PT-2020-16980 · Barco · Barco Wepresent Wipg-1600W

Jim Becher

+1

·

Published

2020-11-24

·

Updated

2021-07-21

·

CVE-2020-28333

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Barco wePresent WiPG-1600W version 2.5.1.8
Description The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions, instead using a SEID token appended to URLs in GET requests. This SEID token can be exposed in web proxy logs and browser history. An attacker who captures the SEID and originates requests from the same IP address can access the device's user interface without knowing the credentials.
Recommendations For version 2.5.1.8, as a temporary workaround, consider restricting access to the web interface to minimize the risk of exploitation. Avoid using the SEID token in GET requests until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28333

Affected Products

Barco Wepresent Wipg-1600W