Vulnerability record · CVE-2020-28333 · published 24 November 2020
CVE-2020-28333: Barco wepresent wipg-1600w firmware information exposure vulnerability
BBarco · Wepresent Wipg 1600w Firmware
Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.
Description
Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160161/Barco-wePresent-Authentication-Bypass.html | Third Party AdvisoryVDB Entry |
| https://korelogic.com/Resources/Advisories/KL-001-2020-006.txt | Third Party Advisory |
| http://packetstormsecurity.com/files/160161/Barco-wePresent-Authentication-Bypass.html | Third Party AdvisoryVDB Entry |
| https://korelogic.com/Resources/Advisories/KL-001-2020-006.txt | Third Party Advisory |
Track CVE-2020-28333 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.