← Back to home
ICSA-19-031-02  ·  Published 2019-04-04  ·  View on CISA ICS-CERT ↗

IDenticard PremiSys (Update A)

CVSS 8.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to view sensitive information via backups, obtain access to credentials, and/or obtain full access to the system with admin privileges.

Remediations

  • IDenticard recommends users upgrade to Version 4.2 to address all three vulnerabilities. This software update is provided free of charge. To obtain the new software update and additional information visit https://identicard.helpdocs.io/article/8ikfxeqgdx-identicard-premi-sys-v-4-2 or contact the IDenticard Technical Support Team at (800) 220-8096.
  • IDenticard also recommends users change the Service Database default username and password.
  • In addition to upgrading to Version 4.2, CVE-2019-3908 requires users to set a new password for the backup/restore feature. For more information see the following link:

Affected Vendors

IDenticard

Affected Products (1)

IDenticard · PremiSys < 4.2

Affected Sectors

Commercial Facilities, Government Facilities, Healthcare and Public Health, Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more