CVE-2024-22388

high

Description

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.

References

https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-01

https://support.hidglobal.com/

Details

Source: Mitre, NVD

Published: 2024-02-06

Updated: 2024-10-17

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High