#VU86199 Improper Authorization in HID Global products - CVE-2024-22388
Published: February 7, 2024
Vulnerability identifier: #VU86199
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-22388
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
iCLASS SE CP1000 Encoder
iCLASS SE Readers
iCLASS SE Reader Modules
iCLASS SE Processors
OMNIKEY 5427CK Readers
OMNIKEY 5127CK Readers
OMNIKEY 5023 Readers
OMNIKEY 5027 Readers
iCLASS SE CP1000 Encoder
iCLASS SE Readers
iCLASS SE Reader Modules
iCLASS SE Processors
OMNIKEY 5427CK Readers
OMNIKEY 5127CK Readers
OMNIKEY 5023 Readers
OMNIKEY 5027 Readers
Software vendor:
HID Global
HID Global
Description
The vulnerability allows a local attacker to bypass authorization checks.
The vulnerability exists due to improper authorization. A local attacker can extract sensitive data when reader configuration cards are programmed.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.