Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware
binary allows malicious actors to create credentials for any site code and card number that is using the default
ICT encryption.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://ict.co/media/1xdhaugi/credential-cloning.pdf |
|
History
No history.
Status: PUBLISHED
Assigner: ICT
Published: 2024-05-06T22:33:03.969Z
Updated: 2024-08-02T01:17:58.493Z
Reserved: 2024-03-21T20:07:00.532Z
Link: CVE-2024-29941
Updated: 2024-08-02T01:17:58.493Z
Status : Awaiting Analysis
Published: 2024-05-06T23:15:06.527
Modified: 2024-11-21T09:08:39.710
Link: CVE-2024-29941
No data.