CVE-2020-3928

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
12/06/2020
Last modified:
18/06/2020

Description

GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:usavisionsys:geovision_gv-as210_firmware:*:*:*:*:*:*:*:* 2.21 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as210:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-as410_firmware:*:*:*:*:*:*:*:* 2.21 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as410:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-as810_firmware:*:*:*:*:*:*:*:* 2.21 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as810:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-as1010_firmware:*:*:*:*:*:*:*:* 1.32 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-as1010:-:*:*:*:*:*:*:*
cpe:2.3:o:usavisionsys:geovision_gv-gf192x_firmware:*:*:*:*:*:*:*:* 1.10 (excluding)
cpe:2.3:h:usavisionsys:geovision_gv-gf192x:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools