VulnerabilityModified
CVE-2021-34600
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users.
MEDIUM 5.5EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-335
- Affected
- telenot/compasx
- Source
- info@cert.vde.com
References
- https://www.x41-dsec.de/lab/advisories/x41-2021-003-telenot-complex-insecure-keygen/Exploit, Third Party Advisory
- https://www.x41-dsec.de/lab/advisories/x41-2021-003-telenot-complex-insecure-keygen/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.