CVE-2024-22388
Estado: ModificadaAlta (7.8)—
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (8)
Hidglobal — Iclass SE Cp1000 Encoder FirmwareHidglobal — Iclass SE Processors FirmwareHidglobal — Iclass SE Reader Modules FirmwareHidglobal — Iclass SE Readers FirmwareHidglobal — Omnikey 5023 FirmwareHidglobal — Omnikey 5027 FirmwareHidglobal — Omnikey 5127ck FirmwareHidglobal — Omnikey 5427ck Firmware
CWE
- CWE-1188
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-22388",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-22388",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-02-15T05:16:03.307503Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 1.4
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "HID Global",
"product": "iCLASS SE CP1000 Encoder",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "iCLASS SE Readers",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "iCLASS SE Reader Modules",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "iCLASS SE Processors",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "OMNIKEY 5427CK Readers",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "OMNIKEY 5127CK Readers",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "OMNIKEY 5023 Readers",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "HID Global",
"product": "OMNIKEY 5027 Readers",
"versions": [
{
"status": "affected",
"version": "All"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-02-06T23:15:08.707",
"references": [
{
"url": "https://support.hidglobal.com/",
"tags": [
"Product"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://support.hidglobal.com/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-037-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-1188"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys."
},
{
"lang": "es",
"value": "Cierta configuración disponible en el canal de comunicación para codificadores podría exponer datos confidenciales cuando se programan las tarjetas de configuración del lector. Estos datos podrían incluir claves de administración de dispositivos y credenciales."
}
],
"lastModified": "2026-06-17T07:11:18.497",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:iclass_se_cp1000_encoder_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA7199D9-8A09-4ABF-926C-BF4739222282"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:iclass_se_cp1000_encoder:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2BB854B8-F5E0-4A00-922C-5B62564DB158"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:iclass_se_readers_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F84C363-45B4-40F9-8C8F-93394F2AF318"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:iclass_se_readers:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "08AA1F70-0EDD-498D-A60A-D7E769765A1B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:iclass_se_reader_modules_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8B5F3AFC-7213-41E7-800A-78BE8CA53515"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:iclass_se_reader_modules:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "70B620F5-3B4E-4728-9066-506105282B91"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:iclass_se_processors_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "95FA7393-0EF9-43A4-9F26-DB48FDC3DAE7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:iclass_se_processors:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "029F78BB-6EFE-4CD1-80F3-2B5D476D049C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:omnikey_5427ck_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70382765-8BA5-4114-9681-BC4118FD6E24"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:omnikey_5427ck:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "095B970F-BDB3-449D-8859-ED942B68EC99"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:omnikey_5127ck_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3AD6E73F-E3CA-412B-986F-8582269C2FC1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:omnikey_5127ck:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "FDB1E42B-DDCE-4333-B9A3-56E046988E40"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:omnikey_5023_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE9661B3-E09D-4A88-AB61-C68E3EC7024C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:omnikey_5023:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BA7B4826-9C1C-4685-AD9A-B2A89069A03F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:omnikey_5027_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1833B4BD-0205-412A-BDEE-FE993620C941"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:omnikey_5027:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "71567BE0-8B74-4AF2-840C-E52A31A95BC2"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}