Back to Database
Status published
Critical
CVE-2023-41920
Authentication Bypass by Primary Weakness in Kiloview P1/P2 devices
Vulnerability Description
The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-41920
Credits & Attribution
No credits recorded in the NVD database.
More from Kiloview
View All →CVE-2025-9265
API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
Critical
10
CVE-2025-8915
Hardcoded TLS private key in Kiloview N30 firmware
High
8.7
CVE-2024-2162
Authenticated Remote Code Execution in Kiloview NDI N series products
High
8.8
CVE-2024-2161
Use of Hard-coded Credentials in Kiloview NDI N series products API middleware
Critical
9.8
CVE-2023-41928
Remote server offers deprecated TLS protocol in Kiloview P1/P2 devices
Medium
5.3
Affected Vendor
Kiloview
View all reports →Affected Software
P1/P2
Vulnerable Versions:
All
Timeline
Official Publish:
July 2nd, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.