CVE-2024-1578
The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration and might result in failed login attempts for end-users. Random characters being dropped from ID card numbers compromises the uniqueness of ID cards that can, therefore, result in a security issue if the users are using the ‘ID card self-registration’ function.
Published:Sep 16, 2024
Last Modified:Sep 20, 2024
EPS:Sep 16, 2024
EPSS Score:0.00072
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Nt-ware
Product
Micard Plus Ble
Nt-ware
Micard Plus Ble
Vendor
Nt-ware
Product
Micard Plus Ci
Nt-ware
Micard Plus Ci
Vendor
Rfideas
Product
Micard Plus Ble
Rfideas
Micard Plus Ble
Vendor
Rfideas
Product
Micard Plus Ble Firmware
Rfideas
Micard Plus Ble Firmware
Vendor
Rfideas
Product
Micard Plus Ci
Rfideas
Micard Plus Ci
Vendor
Rfideas
Product
Micard Plus Ci Firmware
Rfideas
Micard Plus Ci Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
