PT-2026-3100 · Entrust · Cardwizard+1

Published

2026-01-15

·

Updated

2026-01-15

·

CVE-2026-23746

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x through 6.10.4 and versions prior to 6.11.1
Description The software has an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoting channel with unsafe formatter/settings that permit untrusted remoting object invocation. An unauthenticated remote attacker who can reach the remoting port can invoke exposed remoting objects to read arbitrary files from the server and coerce outbound authentication, potentially achieving arbitrary file write and remote code execution via known .NET Remoting exploitation techniques. This could lead to disclosure of sensitive installation and service-account data and compromise of the affected host.
Recommendations Versions 5.x through 6.10.4 should be updated to version 6.10.5 or later. Versions prior to 6.11.1 should be updated to version 6.11.1 or later.

Fix

Deserialization of Untrusted Data

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-23746

Affected Products

Cardwizard
Entrust Instant Financial Issuance (Ifi) On Premise