CVE-2023-50126

MEDIUM

Hozard Alarm System - Missing Encryption

Title source: rule
STIX 2.1

Description

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able to bring the alarm system to a disarmed state.

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 8.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-311
Status published
Products (1)
hozard/alarm_system 1.0
Published Jan 11, 2024
Tracked Since Feb 18, 2026