cve/2024/CVE-2024-1578.md
2025-09-29 21:09:30 +02:00

20 lines
1.4 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-1578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1578)
![](https://img.shields.io/static/v1?label=Product&message=MiCard%20PLUS%20BLE&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=MiCard%20PLUS%20Ci&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0.1.0.4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=0.1.0.7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-1287%3A%20Improper%20Validation%20of%20Specified%20Type%20of%20Input&color=brightgreen)
### Description
The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result in characters randomly being dropped from some ID card reads, which would result in the wrong ID card number being assigned during ID card self-registration and might result in failed login attempts for end-users. Random characters being dropped from ID card numbers compromises the uniqueness of ID cards that can, therefore, result in a security issue if the users are using the ID card self-registration function.
### POC
#### Reference
- https://ntware.atlassian.net/wiki/spaces/SA/pages/11973853216/2024+Security+Advisory+Multiple+MiCard+PLUS+card+reader+dropped+characters
#### Github
No PoCs found on GitHub currently.