go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ITPison OMICARD EDM - Use of Hard-coded Credentials

TVN ID TVN-202206011
CVE ID CVE-2022-32965
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products ITPison OMICARD EDM v5.8~v6.0
Description OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.
Solution Contact tech support from ITPison.
Credit Xin-Yue, Song (CHT Security)
Public Date 2022-08-04
Top