CVE-2020-9023
Last modified
CVE-2020-9023 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iteris | Vantage Velocity Firmware | 2.3.1 |
| Iteris | Vantage Velocity Firmware | 2.4.2 |
References
- https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-no.htmlExploit, Third Party Advisory
- https://sku11army.blogspot.com/2020/01/iteris-vantage-velocity-field-unit-no.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9023?
How severe is CVE-2020-9023?
How do I fix CVE-2020-9023?
Are you affected by CVE-2020-9023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
