CVE-2019-3908: Identicard Premisys Id

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.

Affected products

Published 2019-01-18. Last modified 2026-06-17.