Identicard

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-3907

    Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

    Last Modified: Nov 21, 2024
    Published: Jan 18, 2019

    CVE-2019-3906

    Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.

    Last Modified: Nov 21, 2024
    Published: Jan 18, 2019

    CVE-2019-3908

    Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.

    Last Modified: Nov 21, 2024
    Published: Jan 18, 2019

    CVE-2019-3909

    Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.

    Last Modified: Nov 21, 2024
    Published: Jan 18, 2019

    CVE-2017-14973

    IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?file=logged_in.shtm (aka the edit user page).

    Last Modified: Apr 20, 2025
    Published: Oct 09, 2017
    Items Per Page
    Identicard Vulnerabilities & Security CVEs | CVE-DB