CVE-2019-13028: Minv Electronic Identification Cards Client

High severity, CVSS 8.8. EPSS: 3.7% chance of exploitation in the next 30 days.

An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML page. This is a product from the Ministry of Interior of the Slovak Republic.

Affected products

  • Minv Electronic Identification Cards Client: before 3.0.3 (fixed in 3.0.3); before 3.1.2 (fixed in 3.1.2)

Published 2019-06-28. Last modified 2026-06-17.