Lucene search

K
nvd[email protected]NVD:CVE-2023-0248
HistoryDec 14, 2023 - 9:15 p.m.

CVE-2023-0248

2023-12-1421:15:07
CWE-200
CWE-401
web.nvd.nist.gov
2
kantech
gen1
iosmart
card reader
communication
vulnerability
firmware

CVSS3

5.3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

20.6%

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader’s communication memory between the card and reader.

Affected configurations

Nvd
Node
johnsoncontrolsiosmart_gen_1_firmwareRange<1.07.02
AND
johnsoncontrolsiosmart_gen_1Match-
VendorProductVersionCPE
johnsoncontrolsiosmart_gen_1_firmware*cpe:2.3:o:johnsoncontrols:iosmart_gen_1_firmware:*:*:*:*:*:*:*:*
johnsoncontrolsiosmart_gen_1-cpe:2.3:h:johnsoncontrols:iosmart_gen_1:-:*:*:*:*:*:*:*

CVSS3

5.3

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

20.6%

Related for NVD:CVE-2023-0248