Описание
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 32.0 (исключая)
cpe:2.3:a:telenot:compasx:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00058
Низкий
5.5 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-335
CWE-335
Связанные уязвимости
CVSS3: 7.5
github
около 4 лет назад
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for authorization of users.
EPSS
Процентиль: 18%
0.00058
Низкий
5.5 Medium
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-335
CWE-335