Identicard's vulnerability footprint centers on a narrow portfolio of physical-access-control and identity-management products, including its Premisys ID system and Two-Reader Controller Configuration Manager, which serve as authentication and credential-verification components in building-security infrastructure. The recurring weakness classes—hard-coded credentials and passwords, insecure default configurations, and cross-site scripting in web interfaces—reflect the intersection of embedded authentication logic and web-based administrative tooling typical of this product class. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Identicard over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3909CRITICAL Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention. | Jan 18, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-3906HIGH Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge s | Jan 18, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-3907HIGH Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password). | Jan 18, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-3908HIGH Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can | Jan 18, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-14973MEDIUM IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?file=logged_in.shtm (ak | Oct 9, 2017 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Identicard.
Media articles that mention a CVE ID that affects a product developed by Identicard — matched by CVE ID, not by vendor name.