SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-23806

Sensitive data can be extracted from HID iCLASS SE reader configuration cards.

MEDIUM 5.3EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS
0.25% probability · 17th percentile
CISA KEV
Not listed
Weakness
CWE-285, CWE-287
Affected
hidglobal/omnikey secure elements reader configuration cards firmware · hidglobal/iclass se reader configuration cards firmware
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.