Back to Database
Status published
Medium
CVE-2024-23806
HID Global Reader Configuration Cards Improper Authorization
Vulnerability Description
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23806
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- HID Global reported this vulnerability to CISA.
References
More from HID Global
View All →CVE-2024-22388
Insecure Default Initialization of Resource in HID Global
Medium
5.9
CVE-2023-2904
CVE-2023-2904
Unknown
0
CVE-2021-47859
ActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service Path
High
8.5
CVE-2018-17492
EasyLobby Solo contains default administrative credentials. An attacker could exploit...
High
8.4
CVE-2018-17491
EasyLobby Solo could allow a local attacker to gain elevated...
High
8.4
Affected Vendor
HID Global
View all reports →Affected Software
HID iCLASS SE reader configuration cards, OMNIKEY Secure Elements reader configuration cards
Vulnerable Versions:
All
Timeline
Official Publish:
February 7th, 2024
Last Modified:
June 13th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N