ZeroHour

CVE-2021-34600

PoC
CVSS 3.1
5.5 medium
EPSS
<1%p35
Published
()
Modified
Description

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.

Vendors
telenot
Products
compasx
Weakness
CWE-335
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.