Vulnerability Description
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Assaabloy | Yale Conexis L1 Firmware | 1.1.0 |
| Assaabloy | Yale Conexis L1 | - |
Related Weaknesses (CWE)
References
- https://arxiv.org/abs/2312.00021
- https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-4ExploitTechnical DescriptionThird Party Advisory
- https://arxiv.org/abs/2312.00021
- https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-4ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2023-26941?
CVE-2023-26941 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.
How severe is CVE-2023-26941?
CVE-2023-26941 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26941?
Check the references section above for vendor advisories and patch information. Affected products include: Assaabloy Yale Conexis L1 Firmware, Assaabloy Yale Conexis L1.