| TVN ID | TVN-202203004 |
|---|---|
| CVE ID | CVE-2022-26671 |
| CVSS | 7.3 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| Affected Products | 中興保全Dr.ID 門禁考勤系統 門禁Ver: 3.3.2、考勤Ver: 3.4.0.0.3.11 |
| Description | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service. |
| Solution | 更新中興保全Dr.ID 門禁考勤系統 考勤Ver: 3.4.0.0.3.13_20211214 |
| Credit | Terry Chang、Annie Huang (行政院國家資通安全會報技術服務中心 NCCST) |
| Public Date | 2022-03-31 |
