CVE-2019-3906
Summary
| CVE | CVE-2019-3906 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-18 18:29:00 UTC |
| Updated | 2022-12-03 14:45:00 UTC |
| Description | Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Identicard | Premisys Id | 3.1.190 | All | All | All |
| Application | Identicard | Premisys Id | 3.1.190 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [R3] Multiple Premisys Identicard Vulnerabilities - Research Advisory | Tenable® | MISC | www.tenable.com | Third Party Advisory |
| Identicard Premisys Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.