CVE Published: 06/02/2024 |
CVE Updated: 17/10/2024 |
CVE Year: 2024 Source: icscert |
Vendor: HID Global |
Product: iCLASS SE CP1000 Encoder Status : PUBLISHED
CVE-2024-22388 Description
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
Metrics
CVSS Version: 3.1 |
Base Score: 5.9 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* NONE User Interaction (UI)* NONE Scope (S)* CHANGED