Hardcoded Credentials in Premisys Identicard Version 3.1.190 WCF Service on Port 9003 Vulnerability

Hardcoded Credentials in Premisys Identicard Version 3.1.190 WCF Service on Port 9003 Vulnerability

CVE-2019-3906 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.

Learn more about our Web Application Penetration Testing UK.