PT-2026-3100 · Entrust · Cardwizard+1
Published
2026-01-15
·
Updated
2026-01-15
·
CVE-2026-23746
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x through 6.10.4 and versions prior to 6.11.1
Description
The software has an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoting channel with unsafe formatter/settings that permit untrusted remoting object invocation. An unauthenticated remote attacker who can reach the remoting port can invoke exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, potentially achieving arbitrary file write and remote code execution via known .NET Remoting exploitation techniques. This could lead to disclosure of sensitive installation and service-account data and compromise of the affected host.
Recommendations
Versions 5.x through 6.10.4 should be updated to version 6.10.5 or later.
Versions prior to 6.11.1 should be updated to version 6.11.1 or later.
Fix
Deserialization of Untrusted Data
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cardwizard
Entrust Instant Financial Issuance (Ifi) On Premise