CVE-2020-28333
Barco wePresent Authentication Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.
Los dispositivos Barco wePresent WiPG-1600W permiten una Omisión de Autenticación. Versión(es) afectada(s): 2.5.1.8. La interfaz web Barco wePresent WiPG-1600W no utiliza cookies de sesión para rastrear sesiones autenticadas. En su lugar, la interfaz web utiliza un token "SEID" que es agregado al final de las URL en las peticiones GET. Por lo tanto, el "SEID" estaría expuesto en los registros del proxy web y en el historial del navegador. Un atacante que es capaz de capturar el "SEID" y originar peticiones desde la misma dirección IP (por medio de un dispositivo NAT o proxy web) podría ser capaz de acceder a la interfaz de usuario del dispositivo sin tener que conocer las credenciales
The Barco wePresent WiPG-1600W version 2.5.1.8 web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-06 CVE Reserved
- 2020-11-20 CVE Published
- 2023-11-13 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/160161/Barco-wePresent-Authentication-Bypass.html | Third Party Advisory | |
https://korelogic.com/Resources/Advisories/KL-001-2020-006.txt | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Barco Search vendor "Barco" | Wepresent Wipg-1600w Firmware Search vendor "Barco" for product "Wepresent Wipg-1600w Firmware" | 2.5.1.8 Search vendor "Barco" for product "Wepresent Wipg-1600w Firmware" and version "2.5.1.8" | - |
Affected
| in | Barco Search vendor "Barco" | Wepresent Wipg-1600w Search vendor "Barco" for product "Wepresent Wipg-1600w" | - | - |
Safe
|