PT-2019-16761 · Premisys · Premisys Identicard
CVE-2019-3906
·
Publicado
2019-01-18
·
Atualizado
2022-12-03
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Premisys Identicard version 3.1.190
Description
The issue concerns hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can exploit these credentials to access and modify the badge system database.
Recommendations
For Premisys Identicard version 3.1.190, consider changing the hardcoded credentials in the WCF service to prevent unauthorized access. As a temporary workaround, restrict access to the WCF service on port 9003 to minimize the risk of exploitation.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Premisys Identicard