MEDIUM · 5.9

CVE-2024-22388

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device admi...

Vulnerability Description

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HidglobalIclass Se Cp1000 Encoder FirmwareAll versions
HidglobalIclass Se Cp1000 Encoder-
HidglobalIclass Se Readers FirmwareAll versions
HidglobalIclass Se Readers-
HidglobalIclass Se Reader Modules FirmwareAll versions
HidglobalIclass Se Reader Modules-
HidglobalIclass Se Processors FirmwareAll versions
HidglobalIclass Se Processors-
HidglobalOmnikey 5427Ck FirmwareAll versions
HidglobalOmnikey 5427Ck-
HidglobalOmnikey 5127Ck FirmwareAll versions
HidglobalOmnikey 5127Ck-
HidglobalOmnikey 5023 FirmwareAll versions
HidglobalOmnikey 5023-
HidglobalOmnikey 5027 FirmwareAll versions
HidglobalOmnikey 5027-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-22388?

CVE-2024-22388 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device admi...

How severe is CVE-2024-22388?

CVE-2024-22388 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-22388?

Check the references section above for vendor advisories and patch information. Affected products include: Hidglobal Iclass Se Cp1000 Encoder Firmware, Hidglobal Iclass Se Cp1000 Encoder, Hidglobal Iclass Se Readers Firmware, Hidglobal Iclass Se Readers, Hidglobal Iclass Se Reader Modules Firmware.