CVE-2020-9023

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/02/2020
Last modified:
21/07/2021

Description

Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:iteris:vantage_velocity_firmware:2.3.1:*:*:*:*:*:*:*
cpe:2.3:o:iteris:vantage_velocity_firmware:2.4.2:*:*:*:*:*:*:*
cpe:2.3:h:iteris:vantage_velocity:-:*:*:*:*:*:*:*