PT-2024-18146 · Unknown · Micard Plus Ci+1
Published
2024-09-16
·
Updated
2024-09-20
·
CVE-2024-1578
CVSS v3.1
5.3
Medium
| Vector | AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MiCard PLUS Ci and MiCard PLUS BLE reader products (affected versions not specified)
Description
The issue is related to a firmware fault in the MiCard PLUS Ci and MiCard PLUS BLE reader products, which may cause characters to be randomly dropped from some ID card reads. This can result in the wrong ID card number being assigned during ID card self-registration, potentially leading to failed login attempts for end-users. The randomness of dropped characters compromises the uniqueness of ID cards, posing a security issue when using the 'ID card self-registration' function.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Micard Plus Ble
Micard Plus Ci