CVE-2024-23806

Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hidglobal:omnikey_secure_elements_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:omnikey_secure_elements_reader_configuration_cards:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hidglobal:iclass_se_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:iclass_se_reader_configuration_cards:-:*:*:*:*:*:*:*

History

11 Oct 2024, 16:15

Type Values Removed Values Added
Summary (en) Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys. (en) Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
References
  • {'url': 'https://https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02', 'tags': ['Broken Link'], 'source': 'ics-cert@hq.dhs.gov'}
  • () https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02 -
CWE CWE-285

15 Feb 2024, 05:01

Type Values Removed Values Added
First Time Hidglobal omnikey Secure Elements Reader Configuration Cards Firmware
Hidglobal
Hidglobal iclass Se Reader Configuration Cards Firmware
Hidglobal iclass Se Reader Configuration Cards
Hidglobal omnikey Secure Elements Reader Configuration Cards
References () https://www.hidglobal.com/support - () https://www.hidglobal.com/support - Product
References () https://https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02 - () https://https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-02 - Broken Link
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:h:hidglobal:omnikey_secure_elements_reader_configuration_cards:-:*:*:*:*:*:*:*
cpe:2.3:o:hidglobal:iclass_se_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:hidglobal:omnikey_secure_elements_reader_configuration_cards_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hidglobal:iclass_se_reader_configuration_cards:-:*:*:*:*:*:*:*
CWE CWE-287

07 Feb 2024, 17:38

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-07 17:15

Updated : 2024-10-11 16:15


NVD link : CVE-2024-23806

Mitre link : CVE-2024-23806

CVE.ORG link : CVE-2024-23806


JSON object : View

Products Affected

hidglobal

  • iclass_se_reader_configuration_cards_firmware
  • omnikey_secure_elements_reader_configuration_cards
  • omnikey_secure_elements_reader_configuration_cards_firmware
  • iclass_se_reader_configuration_cards
CWE
CWE-285

Improper Authorization

CWE-287

Improper Authentication