CVE-2021-34600
MEDIUM 5.5EPSS 0.4%
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.
- CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 4.9 MEDIUM
AV:L/AC:L/Au:N/C:C/I:N/A:N - EPSS
- 0.41% chance of exploitation in the next 30 days, 35th percentile
- Published
- 2022-01-20
- Updated
- 2024-09-16
Proof-of-concept exploits (2)
- https://www.x41-dsec.de/lab/advisories/x41-2021-003-telenot-complex-insecure-keygen/
- x41sec/CVE-2021-346003★ · 2022-01-17