CVE-2022-26671
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
07/04/2022
Last modified:
14/04/2022
Description
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:secom:dr.id_access_control:3.3.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:secom:dr.id_attendance_system:3.4.0.0.3.11:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



