CVE-2024-1578 MEDIUM

CVE-2024-1578: Multiple MiCard PLUS card reader dropped characters

Vendor Rebranded By Nt-Ware (Originally Developed And Provided By Rf Ideas)
Product MiCard PLUS Ci
Weakness CWE-1287
Published September 16, 2024
Last update September 16, 2024

CVSS base score

5.3/10
Attack vector Physical
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration and might result in failed login attempts for end-users. Random characters being dropped from ID card numbers compromises the uniqueness of ID cards that can, therefore, result in a security issue if the users are using the ‘ID card self-registration’ function.

Key dates

02Disclosure timeline

September 16, 2024 CVE published
September 16, 2024 Record updated