CVE-2024-22388

MEDIUM
Published Feb 6, 2024 Modified Nov 21, 2024 CWE-1188

Description

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.

Is your site exposed to CVE-2024-22388?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.9
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Weakness Type (CWE)

CWE-1188 CWE-1188

Affected Products

Vendor Product
hidglobal iclass_se_cp1000_encoder_firmware
hidglobal iclass_se_cp1000_encoder
hidglobal iclass_se_readers_firmware
hidglobal iclass_se_readers
hidglobal iclass_se_reader_modules_firmware
hidglobal iclass_se_reader_modules
hidglobal iclass_se_processors_firmware
hidglobal iclass_se_processors
hidglobal omnikey_5427ck_firmware
hidglobal omnikey_5427ck
hidglobal omnikey_5127ck_firmware
hidglobal omnikey_5127ck
hidglobal omnikey_5023_firmware
hidglobal omnikey_5023
hidglobal omnikey_5027_firmware
hidglobal omnikey_5027

References

Frequently Asked Questions

What is CVE-2024-22388? +
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys. It has a CVSS v3.1 base score of 5.9 (MEDIUM).
How severe is CVE-2024-22388? +
CVE-2024-22388 has a CVSS v3.1 score of 5.9 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-22388? +
CVE-2024-22388 affects products from hidglobal, specifically: iclass_se_cp1000_encoder, iclass_se_cp1000_encoder_firmware, iclass_se_processors, iclass_se_processors_firmware, iclass_se_reader_modules, iclass_se_reader_modules_firmware, iclass_se_readers, iclass_se_readers_firmware, omnikey_5023, omnikey_5023_firmware, omnikey_5027, omnikey_5027_firmware, omnikey_5127ck, omnikey_5127ck_firmware, omnikey_5427ck, omnikey_5427ck_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-22388? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-22388 — free, no signup required.