Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published: 2019-01-18T18:00:00

Updated: 2024-08-04T19:26:26.705Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3906

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-01-18T18:29:00.247

Modified: 2024-11-21T04:42:50.283

Link: CVE-2019-3906

cve-icon Redhat

No data.