CVE-2020-3928
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
12/06/2020
Last modified:
18/06/2020
Description
GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:usavisionsys:geovision_gv-as210_firmware:*:*:*:*:*:*:*:* | 2.21 (excluding) | |
| cpe:2.3:h:usavisionsys:geovision_gv-as210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:usavisionsys:geovision_gv-as410_firmware:*:*:*:*:*:*:*:* | 2.21 (excluding) | |
| cpe:2.3:h:usavisionsys:geovision_gv-as410:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:usavisionsys:geovision_gv-as810_firmware:*:*:*:*:*:*:*:* | 2.21 (excluding) | |
| cpe:2.3:h:usavisionsys:geovision_gv-as810:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:usavisionsys:geovision_gv-as1010_firmware:*:*:*:*:*:*:*:* | 1.32 (excluding) | |
| cpe:2.3:h:usavisionsys:geovision_gv-as1010:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:usavisionsys:geovision_gv-gf192x_firmware:*:*:*:*:*:*:*:* | 1.10 (excluding) | |
| cpe:2.3:h:usavisionsys:geovision_gv-gf192x:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



