This content is restricted.
Brief
Here is a short summary of the View CSAF document:
Summary:
A vulnerability has been identified in HID Global's Reader Configuration Cards, specifically in the iCLASS SE and OMNIKEY Secure Elements devices. The vulnerability, rated CVSS v3 5.3, allows an attacker to extract credential and device administration keys from the configuration cards, which could be used to create malicious configuration cards or credentials. HID Global recommends mitigations such as securely destroying unneeded configuration cards, updating readers and credentials with new keys, and hardening readers to prevent malicious configuration changes. CISA also provides additional mitigation guidance and recommended practices for control system security. As of the initial publication on February 6, 2024, there are no known public exploits specifically targeting this vulnerability.
Highlights content goes here...
This content is restricted.
