CVE-2021-34600 MEDIUM

CVE-2021-34600: Telenot complex: Insecure AES Key Generation

Vendor Telenot Electronic Gmbh
Product CompasX
Weakness CWE-335
Published January 20, 2022
Last update September 16, 2024

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.

Key dates

02Disclosure timeline

January 20, 2022 CVE published
September 16, 2024 Record updated