The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building. This issue affects all Be-Tech Mifare Classic card systems. To fix the vulnerability, it is necessary to replace the software, encoder, cards, and PCBs in the locks.
History

Tue, 27 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 May 2025 10:15:00 +0000

Type Values Removed Values Added
Description The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel guest Mifare Classic card can create a master key card that unlocks all the locks in the building. This issue affects all Be-Tech Mifare Classic card systems. To fix the vulnerability, it is necessary to replace the software, encoder, cards, and PCBs in the locks.
Title Unauthorized creation of master key in Mifare Classic Be-Tech cards
Weaknesses CWE-312
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-05-26T10:03:35.047Z

Updated: 2025-05-27T14:23:50.767Z

Reserved: 2025-04-28T21:08:42.323Z

Link: CVE-2025-4053

cve-icon Vulnrichment

Updated: 2025-05-27T14:23:48.357Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-26T10:15:21.190

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-4053

cve-icon Redhat

No data.