PT-2024-18146 · Unknown · Micard Plus Ci+1

Published

2024-09-16

·

Updated

2024-09-20

·

CVE-2024-1578

CVSS v3.1

5.3

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions MiCard PLUS Ci and MiCard PLUS BLE reader products (affected versions not specified)
Description The issue is related to a firmware fault in the MiCard PLUS Ci and MiCard PLUS BLE reader products, which may cause characters to be randomly dropped from some ID card reads. This can result in the wrong ID card number being assigned during ID card self-registration, potentially leading to failed login attempts for end-users. The randomness of dropped characters compromises the uniqueness of ID cards, posing a security issue when using the 'ID card self-registration' function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-1578

Affected Products

Micard Plus Ble
Micard Plus Ci