CVE-2024-22388

HIGHCVSS 7.8/10EPSS 0.17%

Last modified

CVE-2024-22388 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.17%

6.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HidglobalIclass Se Cp1000 Encoder FirmwareAll versions
HidglobalIclass Se Readers FirmwareAll versions
HidglobalIclass Se Reader Modules FirmwareAll versions
HidglobalIclass Se Processors FirmwareAll versions
HidglobalOmnikey 5427ck FirmwareAll versions
HidglobalOmnikey 5127ck FirmwareAll versions
HidglobalOmnikey 5023 FirmwareAll versions
HidglobalOmnikey 5027 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-22388?
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
How severe is CVE-2024-22388?
CVE-2024-22388 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2024-22388?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-22388?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST