Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and card number that is using the default ICT encryption.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ICT

Published: 2024-05-06T22:33:03.969Z

Updated: 2024-08-02T01:17:58.493Z

Reserved: 2024-03-21T20:07:00.532Z

Link: CVE-2024-29941

cve-icon Vulnrichment

Updated: 2024-08-02T01:17:58.493Z

cve-icon NVD

Status : Deferred

Published: 2024-05-06T23:15:06.527

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-29941

cve-icon Redhat

No data.