CVE-2024-22388
Insecure Default Initialization of Resource in HID Global
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.2%KEV nãoPoC —Patch —
Lifecycle
Feb 06, 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
HID Global · iCLASS SE CP1000 EncoderHID Global · iCLASS SE ProcessorsHID Global · iCLASS SE Reader ModulesHID Global · iCLASS SE ReadersHID Global · OMNIKEY 5023 ReadersHID Global · OMNIKEY 5027 ReadersHID Global · OMNIKEY 5127CK ReadersHID Global · OMNIKEY 5427CK ReadersWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →