Vulnerability Description
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Assaabloy | Yale Keyless Smart Lock Firmware | 1.0 |
| Assaabloy | Yale Keyless Smart Lock | - |
Related Weaknesses (CWE)
References
- https://arxiv.org/abs/2312.00021
- https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-4ExploitTechnical DescriptionThird Party Advisory
- https://arxiv.org/abs/2312.00021
- https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-4ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2023-26943?
CVE-2023-26943 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.
How severe is CVE-2023-26943?
CVE-2023-26943 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26943?
Check the references section above for vendor advisories and patch information. Affected products include: Assaabloy Yale Keyless Smart Lock Firmware, Assaabloy Yale Keyless Smart Lock.