CVE-2024-23806

S

ensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hidglobal:omnikey_secure_elements_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:omnikey_secure_elements_reader_configuration_cards:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hidglobal:iclass_se_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:iclass_se_reader_configuration_cards:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References
  • () https://https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02 -
References () https://www.hidglobal.com/support - Product () https://www.hidglobal.com/support - Product

11 Oct 2024, 16:15

Type Values Removed Values Added
References
  • {'url': 'https://https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02', 'tags': ['Broken Link'], 'source': '[email protected]'}
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02 -
CWE CWE-285
Summary (en) Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys. (en) Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

Information

Published : 2024-02-07 17:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23806

Mitre link : CVE-2024-23806

CVE.ORG link : CVE-2024-23806


JSON object : View

CWE
CWE-285

Improper Authorization

CWE-287

Improper Authentication