Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
Se pueden extraer datos confidenciales de las tarjetas de configuración del lector HID iCLASS SE. Esto podrÃa incluir claves de administrador de dispositivos y credenciales.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
| Attack Vector | PHYSICAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | NONE |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-285
|
| [email protected] | Secondary |
en
CWE-287
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| hidglobal | omnikey_secure_elements_reader_configuration_cards_firmware | - | <built-in method update of dict object at 0x7c3c32d53ac0> | Operating System |
| hidglobal | iclass_se_reader_configuration_cards_firmware | - | <built-in method update of dict object at 0x7c3c32d52e40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:omnikey_secure_elements_reader_configuration_cards_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:omnikey_secure_elements_reader_configuration_cards:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:hidglobal:iclass_se_reader_configuration_cards_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:hidglobal:iclass_se_reader_configuration_cards:-:*:*:*:*:*:*:* |