CVE-2024-22388
Insecure Default Initialization of Resource in HID Global
Severity Score
7.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
Cierta configuración disponible en el canal de comunicación para codificadores podría exponer datos confidenciales cuando se programan las tarjetas de configuración del lector. Estos datos podrían incluir claves de administración de dispositivos y credenciales.
*Credits:
HID Global reported this vulnerability to CISA.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-01-25 CVE Reserved
- 2024-02-06 CVE Published
- 2024-02-15 EPSS Updated
- 2024-10-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
- CWE-1188: Initialization of a Resource with an Insecure Default
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://support.hidglobal.com | Product | |
https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hidglobal Search vendor "Hidglobal" | Iclass Se Cp1000 Encoder Firmware Search vendor "Hidglobal" for product "Iclass Se Cp1000 Encoder Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Iclass Se Cp1000 Encoder Search vendor "Hidglobal" for product "Iclass Se Cp1000 Encoder" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Iclass Se Readers Firmware Search vendor "Hidglobal" for product "Iclass Se Readers Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Iclass Se Readers Search vendor "Hidglobal" for product "Iclass Se Readers" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Iclass Se Reader Modules Firmware Search vendor "Hidglobal" for product "Iclass Se Reader Modules Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Iclass Se Reader Modules Search vendor "Hidglobal" for product "Iclass Se Reader Modules" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Iclass Se Processors Firmware Search vendor "Hidglobal" for product "Iclass Se Processors Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Iclass Se Processors Search vendor "Hidglobal" for product "Iclass Se Processors" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Omnikey 5427ck Firmware Search vendor "Hidglobal" for product "Omnikey 5427ck Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Omnikey 5427ck Search vendor "Hidglobal" for product "Omnikey 5427ck" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Omnikey 5127ck Firmware Search vendor "Hidglobal" for product "Omnikey 5127ck Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Omnikey 5127ck Search vendor "Hidglobal" for product "Omnikey 5127ck" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Omnikey 5023 Firmware Search vendor "Hidglobal" for product "Omnikey 5023 Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Omnikey 5023 Search vendor "Hidglobal" for product "Omnikey 5023" | - | - |
Safe
|
Hidglobal Search vendor "Hidglobal" | Omnikey 5027 Firmware Search vendor "Hidglobal" for product "Omnikey 5027 Firmware" | * | - |
Affected
| in | Hidglobal Search vendor "Hidglobal" | Omnikey 5027 Search vendor "Hidglobal" for product "Omnikey 5027" | - | - |
Safe
|