Barco
Barco Wepresent Wipg-1600w Firmware: vulnerabilidades y CVE
Barco Wepresent Wipg-1600w Firmware tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas6
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-3929 | Crítica (9.8) | 99% | ⚠ Explotación activa | 30 abr 2019 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-28329 | Crítica (9.8) | 1.6% | — | 24 nov 2020 | Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticated, administrative… |
| CVE-2020-28334 | Crítica (9.8) | 4.8% | — | 24 nov 2020 | Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included… |
| CVE-2020-28333 | Crítica (9.8) | 3.2% | — | 24 nov 2020 | Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the… |
| CVE-2020-28332 | Crítica (9.8) | 1.1% | — | 24 nov 2020 | Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally… |
| CVE-2020-28330 | Media (6.5) | 1.2% | — | 24 nov 2020 | Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API credentials (retrieved by exploiting CVE-2020-28329) can issue an… |
| CVE-2020-28331 | Alta (7.5) | 1.7% | — | 24 nov 2020 | Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemon included in the firmware image. By default, the SSH daemon is… |
| CVE-2019-3930 | Crítica (9.8) | 7.0% | — | 30 abr 2019 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq… |
| CVE-2019-3929 | Crítica (9.8) | 99% | ⚠ Explotación activa | 30 abr 2019 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Barco
Clickshare Cse-200 Firmware · 9Control Room Management Suite · 9Clickshare Cs-100 Firmware · 6Clickshare Csc-1 Firmware · 6Clickshare Cse-200+ Firmware · 5Clickshare Cse-800 Firmware · 5Transform N · 4Clickshare Button R9861500d01 Firmware · 4Clickshare Csm-1 Firmware · 4Wepresent Wipg-1000p Firmware · 2Mirrorop Windows Sender · 2Clickshare C-5 · 1