CVE-2024-29941
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
06/05/2024
Last modified:
01/08/2024
Description
Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware<br />
binary allows malicious actors to create credentials for any site code and card number that is using the default<br />
ICT encryption.<br />
<br />
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH



