CVE-2019-3908 affects Premisys Identicard version 3.1.190, where backup files are stored as encrypted zip files with a hard-coded, unchangeable password. This vulnerability has a CVSS score of 7.5 (HIGH), indicating that an unauthenticated attacker can remotely access and decrypt these backups to obtain sensitive data. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.190CPE matchmatch criteria | cpe:2.3:a:identicard:premisys_id:3.1.190:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R3] Multiple Premisys Identicard Vulnerabilities
Jan 8, 2019[R3] Multiple Premisys Identicard Vulnerabilities
Jan 8, 2019[R3] Multiple Premisys Identicard Vulnerabilities
Jan 8, 2019