Skip to main content

Improper Authorization

CVE-2024-23806

Severity Medium
Score 5.3/10

Summary

Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

  • LOW
  • PHYSICAL
  • NONE
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-285 - Improper Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

References

Advisory Timeline

  • Published