CVE-2024-23806

Published Feb 7, 2024

Last updated 10 months ago

Overview

Description
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
Source
ics-cert@hq.dhs.gov
NVD status
Modified
Products
omnikey_secure_elements_reader_configuration_cards_firmware, iclass_se_reader_configuration_cards_firmware

Risk scores

CVSS 3.1

Type
Primary
Base score
5.3
Impact score
4
Exploitability score
0.9
Vector string
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

ics-cert@hq.dhs.gov
CWE-285
nvd@nist.gov
CWE-287

Social media

Hype score
Not currently trending

Configurations