CVE-2023-26943: Weak Encryption
Published Dec 4, 2023
·Updated
Weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 allows attackers to create a cloned tag via physical proximity to the original.
Affected Software
2 affected components
All of the following
Assaabloy Yale Keyless Smart Lock Firmware=1.0
Assaabloy Yale Keyless Smart Lock
Event History
Dec 4, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-26943?
CVE-2023-26943 refers to weak encryption mechanisms in RFID Tags in Yale Keyless Lock v1.0 that allow attackers to create a cloned tag via physical proximity to the original.
2
What software is affected by CVE-2023-26943?
The Assaabloy Yale Keyless Smart Lock Firmware version 1.0 is affected by CVE-2023-26943.
3
What is the severity of CVE-2023-26943?
CVE-2023-26943 has a severity level of medium.
4
How can an attacker exploit CVE-2023-26943?
An attacker can exploit CVE-2023-26943 by creating a cloned tag through physical proximity to the original RFID tag.
5
Is the Assaabloy Yale Keyless Smart Lock vulnerable to CVE-2023-26943?
No, the Assaabloy Yale Keyless Smart Lock is not vulnerable to CVE-2023-26943.