TVN ID | TVN-202203004 |
---|---|
CVE ID | CVE-2022-26671 |
CVSS | 7.3 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Affected Products | 中興保全Dr.ID 門禁考勤系統 門禁Ver: 3.3.2、考勤Ver: 3.4.0.0.3.11 |
Description | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service. |
Solution | 更新中興保全Dr.ID 門禁考勤系統 考勤Ver: 3.4.0.0.3.13_20211214 |
Credit | Terry Chang、Annie Huang (行政院國家資通安全會報技術服務中心 NCCST) |
Public Date | 2022-03-31 |