CVE-2019-3906 Vulnerability Details

  /     /     /  

CVE-2019-3906 Metadata Quick Info

CVE Published: 18/01/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: tenable | Vendor: n/a | Product: Premisys Identicard 3.1.190
Status : PUBLISHED

CVE-2019-3906 Description

Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-798
CWE Name: CWE-798 Hard-coded Credentials
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).