#VU25403 Improper Authentication in Vantage Velocity - CVE-2020-9023
Published: February 17, 2020
Vantage Velocity
Iteris, Inc.
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password. A remote attacker can bypass authentication process and gain unauthorized access to the application.