Lucene search

K
cveICTCVE-2024-29941
HistoryMay 06, 2024 - 11:15 p.m.

CVE-2024-29941

2024-05-0623:15:06
CWE-522
ICT
web.nvd.nist.gov
29
insecure storage
ict mifare
desfire encryption
default encryption

CVSS3

8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware
binary allows malicious actors to create credentials for any site code and card number that is using the default
ICT encryption.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "TSEC",
    "vendor": "Integrated Control Technology",
    "versions": [
      {
        "status": "affected",
        "version": "0"
      }
    ]
  }
]

CVSS3

8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-29941