CVE-2023-0248
Estado: ModificadaMedia (5.3)—
Un atacante con acceso físico al lector de tarjetas Kantech Gen1 ioSmart con versión de firmware anterior a 1.7.2 en determinadas circunstancias puede recuperar la memoria de comunicación del lector entre la tarjeta y el lector.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200, CWE-401
- CWE-401
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-0248",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-0248",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-13T21:03:38.527676Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "productsecurity@jci.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 5.3,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "productsecurity@jci.com",
"affectedData": [
{
"vendor": "Sensormatic Electronics, a subsidiary of Johnson Controls, Inc.",
"product": "ioSmart Gen1",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.07.02",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-14T21:15:07.553",
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-02",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "productsecurity@jci.com"
},
{
"url": "https://www.johnsoncontrols.com/cyber-solutions/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "productsecurity@jci.com"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-23-348-02",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.johnsoncontrols.com/cyber-solutions/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productsecurity@jci.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-401"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.\n\n"
},
{
"lang": "es",
"value": "Un atacante con acceso físico al lector de tarjetas Kantech Gen1 ioSmart con versión de firmware anterior a 1.7.2 en determinadas circunstancias puede recuperar la memoria de comunicación del lector entre la tarjeta y el lector."
}
],
"lastModified": "2026-06-17T05:25:07.313",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:johnsoncontrols:iosmart_gen_1_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2EAD2797-79E8-4ED4-87EC-914F08698414",
"versionEndExcluding": "1.07.02"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:johnsoncontrols:iosmart_gen_1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1FC9CD38-BBD7-4AB8-A7E1-87246BCD7812"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "productsecurity@jci.com"
}