Vulnerability Description
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Secom | Dr.Id Access Control | 3.3.2 |
| Secom | Dr.Id Attendance System | 3.4.0.0.3.11 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-5971-b691f-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-5971-b691f-1.htmlThird Party Advisory
FAQ
What is CVE-2022-26671?
CVE-2022-26671 is a vulnerability with a CVSS score of 7.3 (HIGH). Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system inf...
How severe is CVE-2022-26671?
CVE-2022-26671 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26671?
Check the references section above for vendor advisories and patch information. Affected products include: Secom Dr.Id Access Control, Secom Dr.Id Attendance System.