Lucene search

K
cvelistJciCVELIST:CVE-2023-0248
HistoryDec 14, 2023 - 8:57 p.m.

CVE-2023-0248 Kantech Gen1 ioSmart card reader

2023-12-1420:57:33
CWE-401
CWE-200
jci
www.cve.org
2
cve-2023-0248
kantech gen1
iosmart card reader
firmware version
communication memory

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

20.6%

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader’s communication memory between the card and reader.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ioSmart Gen1",
    "vendor": "Sensormatic Electronics, a subsidiary of Johnson Controls, Inc.",
    "versions": [
      {
        "lessThan": "1.07.02",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

20.6%

Related for CVELIST:CVE-2023-0248