SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-22388

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed.

HIGH 7.8EPSS 0.17%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.17% probability · 6th percentile
CISA KEV
Not listed
Weakness
CWE-1188
Affected
hidglobal/iclass se cp1000 encoder firmware · hidglobal/iclass se readers firmware · hidglobal/iclass se reader modules firmware · hidglobal/iclass se processors firmware · hidglobal/omnikey 5427ck firmware · hidglobal/omnikey 5127ck firmware · hidglobal/omnikey 5023 firmware · hidglobal/omnikey 5027 firmware
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.