Telenot complex: Insecure AES Key Generation
Vulnerability Description
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-34600
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- X41 D-SEC GmbH, Markus Vervier, Yasar Klawohn
Affected Vendor
Telenot Electronic GmbH
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.