CVE-2024-39342
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated per installation of the software. Combined with the encrypted password that can be obtained from "WebAPI.cfg.xml" in CVE-2024-39341, the decryption is trivial and can lead to privilege escalation on the Windows host.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- Base score: 6.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.11%
- Percentile among all scored CVEs: 1
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-269
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-39342",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-39342",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-23T19:39:09.487232Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 4.7,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:entrust_instant_financial_issuance:entrust_instant_financial_issuance:*:*:*:*:*:*:*:*"
],
"vendor": "entrust_instant_financial_issuance",
"product": "entrust_instant_financial_issuance",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "6.10.0"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "6.9.0"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "6.9.1"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "6.9.2"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "6.8.x"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-09-23T18:15:05.570",
"references": [
{
"url": "https://gist.github.com/VAMorales/21a8700a67d80c263b38e693fd528313",
"source": "cve@mitre.org"
},
{
"url": "https://trustedcare.entrust.com/login",
"source": "cve@mitre.org"
},
{
"url": "https://www.entrust.com/",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom AES encryption process that relies on static hard-coded key values. These keys are not uniquely generated per installation of the software. Combined with the encrypted password that can be obtained from \"WebAPI.cfg.xml\" in CVE-2024-39341, the decryption is trivial and can lead to privilege escalation on the Windows host."
},
{
"lang": "es",
"value": "Entrust Instant Financial Issuance (antes conocido como Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, 6.8.x y versiones anteriores utilizan una librería DLL (es decir, DCG.Security.dll) con un proceso de cifrado AES personalizado que se basa en valores de clave estáticos codificados. Estas claves no se generan de forma única por instalación del software. Combinado con la contraseña cifrada que se puede obtener de \"WebAPI.cfg.xml\" en CVE-2024-39341, el descifrado es trivial y puede provocar una escalada de privilegios en el host de Windows."
}
],
"lastModified": "2026-06-17T07:41:45.420",
"sourceIdentifier": "cve@mitre.org"
}