CVE-2021-34600
MEDIUMTelenot CompasX <32.0 - Info Disclosure
Title source: llmDescription
Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used in the NFC tags used for local authorization of users. This may lead to total loss of trustworthiness of the installation.
Exploits (1)
Scores
CVSS v3
5.5
EPSS
0.0006
EPSS Percentile
18.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-335
Status
published
Products (1)
telenot/compasx
< 32.0
Published
Jan 20, 2022
Tracked Since
Feb 18, 2026