PT-2023-18193 · Smr · Smr

Published

2023-02-09

·

Updated

2023-02-21

·

CVE-2023-21426

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SMR versions prior to Jan-2023 Release 1
Description A hardcoded AES key is used to encrypt card emulation PINs in NFC, allowing attackers to access the PIN.
Recommendations For versions prior to Jan-2023 Release 1, update to Jan-2023 Release 1 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-21426

Affected Products

Smr