Vulnerabilities > CVE-2019-3907 - Use of Password Hash With Insufficient Computational Effort vulnerability in Identicard Premisys ID 3.1.190

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
identicard
CWE-916

Summary

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).

Vulnerable Configurations

Part Description Count
Application
Identicard
1