CVE-2024-23806
Published Feb 7, 2024
Last updated a month ago
Overview
- Description
- Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 4
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Severity
- MEDIUM
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:hidglobal:omnikey_secure_elements_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8EC7A2CF-0FC7-43A7-B92A-3C90118A36A7" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:hidglobal:omnikey_secure_elements_reader_configuration_cards:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4489CAC5-5127-40FA-A134-0F609A64FF90" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:hidglobal:iclass_se_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28970D60-1C55-4786-AFC2-DCDE2AE646C1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:hidglobal:iclass_se_reader_configuration_cards:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3F892E2E-A44A-4E04-B9C7-E2686A9274EE" } ], "operator": "OR" } ], "operator": "AND" } ]