Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cg49-x3j6-7j3g

Опубликовано: 26 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.8

Описание

The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building.

This issue affects all Be-Tech Mifare Classic card systems. To fix the vulnerability, it is necessary to replace the software, encoder, cards, and PCBs in the locks.

The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building.

This issue affects all Be-Tech Mifare Classic card systems. To fix the vulnerability, it is necessary to replace the software, encoder, cards, and PCBs in the locks.

EPSS

Процентиль: 3%
0.00016
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-312

Связанные уязвимости

nvd
9 месяцев назад

The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building. This issue affects all Be-Tech Mifare Classic card systems. To fix the vulnerability, it is necessary to replace the software, encoder, cards, and PCBs in the locks.

EPSS

Процентиль: 3%
0.00016
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-312