CVE-2024-29941

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
06/05/2024
Last modified:
01/08/2024

Description

Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware<br /> binary allows malicious actors to create credentials for any site code and card number that is using the default<br /> ICT encryption.<br /> <br />

References to Advisories, Solutions, and Tools