VulnerabilityModified
CVE-2024-22388
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed.
HIGH 7.8EPSS 0.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.17% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1188
- Affected
- hidglobal/iclass se cp1000 encoder firmware · hidglobal/iclass se readers firmware · hidglobal/iclass se reader modules firmware · hidglobal/iclass se processors firmware · hidglobal/omnikey 5427ck firmware · hidglobal/omnikey 5127ck firmware · hidglobal/omnikey 5023 firmware · hidglobal/omnikey 5027 firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://support.hidglobal.com/Product
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-01Third Party Advisory, US Government Resource
- https://support.hidglobal.com/Product
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.