CVE-2019-3906
Estado: ModificadaAlta (8.8)—
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.89%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-798
- CWE-798
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-3906",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vulnreport@tenable.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Premisys Identicard 3.1.190",
"versions": [
{
"status": "affected",
"version": "Premisys Identicard 3.1.190"
}
]
}
]
}
],
"published": "2019-01-18T18:29:00.247",
"references": [
{
"url": "http://www.securityfocus.com/bid/106552",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "vulnreport@tenable.com"
},
{
"url": "https://www.tenable.com/security/research/tra-2019-01",
"tags": [
"Third Party Advisory"
],
"source": "vulnreport@tenable.com"
},
{
"url": "http://www.securityfocus.com/bid/106552",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.tenable.com/security/research/tra-2019-01",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnreport@tenable.com",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents."
},
{
"lang": "es",
"value": "La versión 3.1.190 de Premisys Identicard contiene credenciales embebidas en el servicio WCF en el puerto 9003. Un atacante remoto autenticado puede usar estas credenciales para acceder a la base de datos del sistema \"badge\" y modificar su contenido."
}
],
"lastModified": "2026-06-17T02:35:50.517",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:identicard:premisys_id:3.1.190:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DB2F3CF-B710-4334-9353-C34A97FA1E82"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnreport@tenable.com"
}