Sensitive Data Exposure via Communication Channel Configuration
CVE-2024-22388

5.9MEDIUM

What is CVE-2024-22388?

Certain configurations within the communication channel of HID Global encoders may inadvertently expose sensitive information during the programming of reader configuration cards. This exposure can lead to unauthorized access to critical data, including administrative keys and authentication credentials, which can significantly compromise the security posture of organizations relying on these affected devices. Proper environmental security measures and configuration protocols are essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

iCLASS SE CP1000 Encoder All

iCLASS SE Processors All

iCLASS SE Reader Modules All

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Credit

HID Global reported this vulnerability to CISA.
.