PT-2024-23162 · Ict · Ict

Thomas Hobson

·

Published

2024-05-06

·

Updated

2024-08-01

·

CVE-2024-29941

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions ICT (affected versions not specified)
Description Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and card number that is using the default ICT encryption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-29941

Affected Products

Ict