PT-2026-3100 · Entrust · Cardwizard+1

CVE-2026-23746

·

Publicado

2026-01-15

·

Atualizado

2026-01-15

CVSS v4.0

9.3

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x through 6.10.4 and versions prior to 6.11.1
Description The software has an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoting channel with unsafe formatter/settings that permit untrusted remoting object invocation. An unauthenticated remote attacker who can reach the remoting port can invoke exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, potentially achieving arbitrary file write and remote code execution via known .NET Remoting exploitation techniques. This could lead to disclosure of sensitive installation and service-account data and compromise of the affected host.
Recommendations Versions 5.x through 6.10.4 should be updated to version 6.10.5 or later. Versions prior to 6.11.1 should be updated to version 6.11.1 or later.

Correção

Deserialization of Untrusted Data

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23746

Produtos afetados

Cardwizard
Entrust Instant Financial Issuance (Ifi) On Premise