CVE-2023-0248

HIGH

Kantech Gen1 ioSmart <1.07.02 - Info Disclosure

Title source: llm
STIX 2.1

Description

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0030
EPSS Percentile 21.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-401
Status published
Products (1)
johnsoncontrols/iosmart_gen_1_firmware < 1.07.02
Published Dec 14, 2023
Tracked Since Feb 18, 2026