CVE-2023-26941: Weak Encryption
Published Dec 4, 2023
·Updated
Weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0 allows attackers to create a cloned tag via physical proximity to the original.
Affected Software
2 affected components
All of the following
Assaabloy Yale Conexis L1 Firmware=1.1.0
Assaabloy Yale Conexis L1
Event History
Dec 4, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-26941?
CVE-2023-26941 refers to weak encryption mechanisms in RFID Tags in Yale Conexis L1 v1.1.0, which allows attackers to create a cloned tag via physical proximity to the original.
2
What software is affected by CVE-2023-26941?
The Yale Conexis L1 v1.1.0 firmware is affected by CVE-2023-26941.
3
What is the severity of CVE-2023-26941?
The severity of CVE-2023-26941 is medium with a CVSS score of 6.5.
4
How can the vulnerability in CVE-2023-26941 be exploited?
Attackers can exploit the vulnerability in CVE-2023-26941 by creating a cloned tag through physical proximity to the original RFID tag.
5
Is the Assaabloy Yale Conexis L1 device vulnerable to CVE-2023-26941?
No, the Assaabloy Yale Conexis L1 device itself is not vulnerable to CVE-2023-26941.