6.5
CVE-2023-26941
- EPSS 0.18%
- Veröffentlicht 05.12.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 07:52:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Assaabloy ≫ Yale Conexis L1 Firmware Version1.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.077 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://arxiv.org/abs/2312.00021
https://www.researchgate.net/publication/375759408_Technical_Report_-_CVE-2022-46480_CVE-2023-26941_CVE-2023-26942_and_CVE-2023-26943#fullTextFileContent