HID Offers Year Of Free Elite Keys Responding To HID Standard Key Vulnerability

Published Aug 14, 2024 18:02 PM

An HID vulnerability exposed iCLASS SE and Seos standard keys, increasing risks for HID users. Now, HID has responded to IPVM, saying they are offering a year of free Elite keys.

IPVM Image

This report examines HID's response to IPVM, how this offering addresses the vulnerability, and what issues remain.

"Elite" *** ***

*** ****** **** ** ***** *** "***** ********** ********," ***** **** *********** ************** ** what ** ********* ** "****** ************** keys *** **** ********."

Positives *** *****

****** ******** ****, ***** *** ****** across ******** *************, ***** **** *** specific ** ************* ** ****** ****** a *** ************* ** *********** ** an **********. ***** **** ********* *** vulnerability (***** *** ***** ** ***** a ***) ** *** ******** *** configuration ***** **** *** **** ****, requiring ********* ** **** ******** ****** to ***** ******* ** ******* *** keys.

HID ********

*** ********* ** ***'* **** ******** to ****, ************ *** ********** ** Elite **** *** *** **** *****:

*** ** ********* ** ************, *** to *** ******** ** *** ******** and *********, ***** ** *** ** published ******* ******** ********** *** ******** contacted ********* ** **** **** ** January. ** **** **** ** ********** that *** ** *** ******** **** have **** ******** ******, *** ** have **** ******* **** *** *********** that ********** *** ******** ****** ** responsibly ******** *** ********* *** ********* security ********. **** ** *** ******** keys **** ******** ******, ***** *** a ****** ** *******, *********** ***** a *** ***** ***** **** ** take ** ******* ********* ******, *** the ***** ***** **** ** **** intricate ********* ** *** ************ *** custom *****.

** ** ********** *******,Elite **** and Custom Keys greatly ****** *** **** of the potential issues by using customer-specific keys. Provided Elite Key and Custom Key customers secure their configuration cards and CP1000 encoders from unauthorized access, they are not exposed to this threat, as an attacker cannot obtain these customer-specific keys even with access to a credential.

** ****** **** * ****** ********* away **** ******** ****,we *** ******* ***** *** **** *** *** ***** ** ****** *** *** ******** *** ****** ** **********. We also created a new tool and process for customers to roll to new Elite keys by updating their existing cards. We are also offering customer support to assist our customers with the upgrade process. We continue to further improve our products in light of the reported issues by providing additional remediation steps to customers. These additional remediation ******* **** ** ********* **** ****. Information regarding these remediation options will be shared in our updated PSAs. Once available, we recommend that customers implement these new steps as soon as they are able. [emphasis added]

***'* ********** ********:

** ****** **** * ****** ********* away **** ******** ****, ** *** waiving ***** *** **** *** *** first ** ****** *** *** ******** who ****** ** **********. *** *** Elite ******* ******** ***-**** ********* **** a ****** ************** *** ** ******** their ******** ********. ** ****** ** the *** ***** *******, ***** *** first ***** ** ******** * ******* form *** *** **** ********* ** an ********** ************** ** **** **** through *** ******* ** ****** ***** unique *** ******** *********. *** ******* utilizes ********** *** **********, ********* ****** control ****, ************, ** ***********/******* *** place ***** ****** ******** **** ***. This ******* ******* **** *** *** user *** ******* **** ***** ****** control ********* **** ****** ** ***** keys. *** **** *** **** * size ********** ** *********** ** *** HID ***** ******* *** *** ******* any ******** **** ********* *** ***** through *** ********** ********. *** ******* based ** ******* **** ***** ** an ********* ** ******** *********. ** such, ** ********* *** *** **** interested ** *** ******* ** ******* their *** ************** *** * ************ consultation.

Constraints ** *****

*** ********* ******* ************ *** **** that ***** **** **** ******* ********** by *** (*** ***** ******* ****). *** *******, **** ************ *** use ** ***** **** ******* **** year *** ***** **** *** ******* requires ********* **** ******** ****** ** HID **********, ** **** ** *** use ** ********** ***********. **** ***** HID ** ******* ** ***** **** and *** **** *** ****** *** too ***** *** ***** *** **************.

Costs *** *********

*** **** *** *** ***** *** is ***** ***** ******** ** *** cost ** ************* ******** ******* *** credentials ********* ***** ***'* ******** ****.

*** **** **** ** ** ****** HID ******* ********* *** ** ***, physically ***** ** **** ****. *** example, ******* ****** * "*****, ********* *******" for "****** ********* *******"******* **** ****, * ****** ********* was *** **** ** ********** ** this. *******, ** **** ****, *** knew *** *** *** ******** **** Seos ******** **** **** ********.

********, **** **** ** ****** ***** existing *********** ***** ** *******, **** a*********** ** **** ** ~$*,***, *** purchase *********** ******* *** ***** ***********. Users **** **** ** ****** ***** readers *** ** *** **** ***** keys.

***'* ******* ***** ***** *** ***** ID ******** *** ******** ****:

IPVM Image

Question ** ***** ******** ** ***

***** **** **** ** ***'* ******* offering, ***** **** **** ** ***** "next-generation," ** ********* ******** ** ******* HID ****** **** ***** ******** **** going *******. ***'* ********** **** **** repeatedly **** *******, ******* *** **** that **** **** ****** *** *****.

Comments (24)
Avatar
Mistial Developer
Aug 14, 2024

**** ***** *** ** ******* ** Elite **** *** *** **** *** system *** *** ***** *** ***** key **************.

********* ** **** *** ****, *** might **** ** ******** *** **** (mobile) ******* ** *** (*****).

*** **** ***** ***** ********** *** keys ** **** *** *** ** them ********, ******. *** ******* **** through *** ***, ** *** ***'* need ** ** ******* * ***-******** process. ** *** **** ** *** the *****, *** *** **** ******** a ****** *** **********.

*** **** ****** **** ***** ********* Guide

*** **** ******* ***** ******, *** and ***** *** *** *** **** that *** *** ********* ***** * reader ** **** *** ****** **** reconfiguring **** *******. ****** ******* *** only ** ************ ** ********** *****, which ***** ** *** **** *** certain ************ ***** ****** ***'* **** turn **** **** **, **** ** they *** ****** *** ******.

*** ****, **** *****, *** ********** customer-specific. **** ***** *** ****** ** be ******* ******* * ****** ** well *** ********** *****.

*********: *****'* * ***. **'* * couple ***** * **** * **** for ***-******, *** **** ** * significant **** *** ******* *************. **'* presently ****** ****.

** ***** ** **** **** ** HID ******* ********* ** ***** ***** with ***** *** **** ** ******** form. ** ***** *********** ***** *** barrier ** ********* ******** ********-******** ****, while *** *********** *** ********** *********** Elite ***. * **** ****** ****** as ** ****.

(1)
(5)
MK
Mert Karakaya
Aug 14, 2024
IPVMU Certified

******!

** *** *** **** **** **** of *** *******, *** ***** **** to **** ***** **** ** *** card *********** *** ***** *******.

UI
Undisclosed Integrator #1
Aug 14, 2024

** ****'* *** ******** *** ******* systems ********** *** ***'* ***** ********** Programs?

(1)
Avatar
Tyler Graham
Aug 15, 2024

**, *** **** *** **** *** mobile ***********.

Avatar
Tyler Graham
Aug 15, 2024

**** *** **** ****** ** ***** key? * ****'* ******* **** ***** discriminate *** ***** ***********.

UI
Undisclosed Integrator #1
Aug 15, 2024

* **** *** *** **** * applied. *** **** ******* **** *** HID *********** ******** ** **** ************* is *** ******* **** ******* ** HID ** ************ ***** **** *** smaller ******* *** **********. ***** **** a ***** **** ** ** **.

**** **** *** ******* **** *** en *****? ** ***** * **** of **** ********* **** ******* ******* PKI?

MK
Mert Karakaya
Aug 15, 2024
IPVMU Certified

**#*, **** **** ********* ******* *** for *** ************ (**********), **** **,***,*********, **********.

*******, ** **** *** **** * widespread ************** *** ********** ***. ***** are *********** ********, **** *** ***, *** **** are *** ** ** ***** *********** in ******** *******.

** *** **** ******** ***** *********** for *** *** **** ***** **** as **** ****** ******.

UI
Undisclosed Integrator #1
Aug 16, 2024

****'* *** ******** ***-**********, ******** ************** for *** ************ ******** ** ****? Is ***** * *** *********** ********* equivalent? **** **** *** ********** (****** or *******) ** *** ****** ***; who *********, ***** *** *********** *** private ***? **** ********* ** *****? What ***** ******* ***********?

IPVM Image

IPVM Image

MK
Mert Karakaya
Aug 16, 2024
IPVMU Certified

*** ***, *** *********** **** **** *** public *** ******* ****. ****** **** are ********* ** ** ******** ********, and ******* **** *** **** *** access.

IPVM Image

*** ******-******* *** ***** *** ************ by *** ******** ********. *** **** requires *-***** ** **, ***** *** be *** **** ********** *** ***/***********/**** etc.

*** ** *** ****** **** *** PACS *** **** *** ***** ******, like *********, ***, ***.

** **** ** ** **-***** ****** on ***.

Avatar
Steve Bell
Aug 21, 2024

****** **** *** *** ********* ******** mention, ** ** **** ** ***** credentials *** ******** ******** *** ******* that *** ** * ***** ******** but ********* *** ****** ** ************** for ***** ** ****** ********** **** wanting ******** ****** *******. ** *******, they **** ******* ****** ***** *** same **********, **** ** ** ****** much *** **** ********.

*********** ***** ** ********* ****, ***** every ****** (*** **** ********* **** is **'* *********) *** ** **** that **** *** ********** * ******** risk ** ***** ***** ** ** some **** ** ********* *** *** loading ********* *** ******* ***** ****. So ***** ** ****** ** *********** for * ******** ************* ** **** up ** **** *******. **** **** gets ** ** * ***** ***** all *** *********, *** **** *** paid *** *****, ***** *** **** default *** ** ** ******* **'* of *******'* ******* ****** *** **** with ***** **** ** ****.

**** ** **** **** ** ******* our "****** *******" ********** (******** ** 2016) ** ******* **** * ****** Key ***** ********** *** *** **** for ********, ** ******** *** ********* authentication ************ *** **** *** *** punt ** * ******** **** *** going ****** *** *** ************** *** could ** **** *** ******** ****** with ****** *******. **** **** * certification ******* ** ** *** **** our ********* **** ********* **** *** authenticators **** * ********.

*****, ** **** **** **** *** have * *** *** **** *****, part ** *** *** **** ****** be ** ****** *** **** ** all *** ******* *** *****, ** their ****** * *** * ******* of * **** ** **** ****** all *** *****. *** *** **** HID ***** *** ********* ** ** these ******** ***** **** ******** **** not ******. ** **** ********* ******** made * "******* *********" **** *** the ******** *** ******** ** *** system **** ** **** ** ** pushed *** **** *** ******, ** with *** ********* *************** (***** *** CVE ****) *** *** *** **** to *** ***********, ******* *** */* boards *** ** ***** *** **** can ** ******* *********.

**** *** * ******* ** ***** pretty ******** ***** "*********" *******, *** we ** *** *** ** **** any ******** ***** **** ****** **** our *********, *** * ** **** that ***** *** *** ********* ******* are ******* ** *** **** *** getting * **** *****'* *****.

(1)
(1)
MK
Mert Karakaya
Aug 15, 2024
IPVMU Certified

** **#*,

** ******* *** ** *** ***** clarifications ** *** ***** *** ******* and ***********. ** **** ****** **/**** we ******* * ********.

(1)
Avatar
Mistial Developer
Aug 16, 2024

****'* * **** **** ********. *'** reached *** ** ** ***** ******** at *** ** *** ** **** if ***** ** * *****, *** am ******* **** ****. *'** **** some ****** ***** ******* **** *********, and ***'* **** ** *****'* ********** a ******* **** ** ***.

*** ** *******, * ********* ****** put **** ***** ** *** (** they ***** ** *** ** **** them **), ** ****** *** ****. Custom **** *** **** ** **** I *** ******* **** ** *** customer, *** ***** *********** **** ******** can ******* ****. **'* ******** *** of *** **** ********* ******* *** the ****** ** *****.

(1)
UE
Undisclosed End User #2
Aug 14, 2024

** ** **** *** **** **** format, ** ***** **** **** **** that ** ***** ** **** **** standard ****?

MK
Mert Karakaya
Aug 14, 2024
IPVMU Certified

***#*,*** ****** **** **** ***************** ** ***** ******* ********* ***** in *** **** *** ******* *** facility **** *** **** *** ****.

*** ********* **** ******* ****** *** to ******* ***-**** ********* **** * card ****** **** ** ********* ************ for **** ********** ***-**** ********. ****** this *******, *** *** ******* *** end-user **** **** *,***,*** ********** **** numbers ****** *** ******** ******. **** numbers *** ******* ** *** ************* process ** ****** **** **** ******* are *** **********.

*******, *** ***** **** ** *** Elite **** ** *** ** ****, if *** ***’* ******* **** ****.

*** ***’* **** ** ***** *** Corp ****:

IPVM Image

(1)
UE
Undisclosed End User #2
Aug 14, 2024

****** ****!

Avatar
Mistial Developer
Aug 16, 2024

*** ******* **** ****** (**** ********* 1000 ******) ** **** * ********, and ********* ******** * ******* **** + **** ******, ** ******** **** plus **** ******.

**** **** *** ** *********** (**** it ** **** ****), ** ********* (SIO) **** ** ** **** *** SE ***********.

*** **** ** **** *** *** do ********* **** **** ********* **** Prox ** **** *** **** *** data ******* *** **** *** ***** reprogramming *** *****.

** *** *** ********** ** *** wiegand ****, *** *** ** ******** Key, ** *** *** ** ****** Key, ** *** *** ** ***** (customer-specific *** *******).

********* **** ** ********* * ***** on *** *** ******* ***** **** that ******/******** ** ***** ******. *** won't ********* **** ****** ** ***** people ** ******.

**** ** ***** ********** ***** ** long ** *** **** *** ******, in **** **** *** ********** *********** not ************* ***********. ******* *** ******** the **** *** ************* **** ***** own ***** *** ****** ***** *****.

***** ** * *********** ** * technical *** ********** *******. *** **** are **** *** ***, *** *** won't **** ******** **** **** ** other ****** ******* **** *******.

***** ****** ********** *** ***** ** a ********** ******, ******* *****'* *** many ********** ***** ******* ***** ********** elite **** (*** ** ******** **** encoder **** **** ********), *** *** make *** ** ***** ***** (***** your ******* ***** ******** ** ********** for ********* **** ******). **** ** you **** **** ** - **** and ******* ***** ** ****** ** far ** *** **** **** ****, but ******* ***** **** ****** *** Prox **** **** ******, ******* *** Prox ****** ** ********** ******** ****** the ****** ***** ******* **** ** the ****.

(1)
(1)
UE
Undisclosed End User #3
Aug 16, 2024

** ******** **** ***. ** **** uses *** *****/ *** *** *** my ******* **** *********** ****** ** my ***** *** *** **** ** replicate ** **** ** ********. *** told ** **** ** *** *** it *****, *** **** ** ** experience **** **.

(1)
(1)
Avatar
Charles Baker
Aug 16, 2024

******** & ********:

** ***** *** **** ***********/********** *** amount ** ****** *****, ****, ********* etc ******* ** ******* ******* *** duplicating * ****?

***** * ********** ********** *** *********** the **** ** ** ***** ** this ************* (***** *** ****), ** would ** ******* ** ********* *** technical ******* **** **** ********** *** degree ** ********** * ****** *** actually ****** * ****** ** *) the ******* *** *) **** ** real ******** ** ************ ********.

** ***** **** ********** ** * far ****** *** ** *** **** a ******** ** ******* ****** ***** to.

** * ****** **** **** ***** card ****** ******** ** *** **** level, * ***** ******* **** * reader/keypad ** *** **** **** ********** step ** ******** ******* ********* *** of *** ***** ********** *** ********** access (********* *** ****, ********* *** know, *** ********* **********).

****** ******* *** ******* ************ **** hacking ***'* **** ** ****, **** become **** ******* ** *** ***** available ******** ** *******, *** ***** will ****** ** ***-***-**** **** ***** who **** "**** * ***" ** defeat **** *** **** ****** *** massively *********** *********** ** ********** *** reader.

***** *******: **** *** ******* ** Ai ** *** **** ***** ******** with ****** *********** **********, ******* *****-*** solution *** ********** ******* ** ** activated ****** ** **** "********" ****** location ** *******/****** **** *** ***** is ****** *** ***** **** ** swipes * **** ** * ******. If ***, ***** ********** *** *** points ********.

******** *****.........

MK
Mert Karakaya
Aug 16, 2024
IPVMU Certified

*******, ****** *** *** *******.

** ***** **** ********** ** * far ****** *** ** *** **** a ******** ** ******* ****** ***** to.

* ***** **** ********** ** *** easier **** ******* ***** ** ***** attacks. *******, ***** *** ********** ***** that ** ******** ****** ******** ***** way ****. ***** ******* **** ****** server *****, ******** ****, ***.

**** *** *********, ******* ***** ********* methods *****, **** ********-****** ************ (***, biometric, ***.), ***** **********, ******* ****** and ****** *********, ***.

*******, ** ******** *************, ** **** to ******** *** ******* *** *** any ***************, ******* *********/*** ****** **** need ** ******* **** ** ***** through *** ********.

(1)
Avatar
andrew fulton
Aug 19, 2024
AFAP Consultancy

* **** ***** **** ** ** hard ** *** **** ** ****** numbers ** ****** ***** *** *****. I *** ***** * *** ******* for * ******** **** **** ******** card ****** ** *** *** **** swipes **** **** ** ******* **** were *** *** ***** *** *** person ** **** ********** **** *** journey ** *******. * ***** ***** a *** ** ****** ***** *** it *** * ********** ***** ****** cards, ** ******* **** **** * had ********.

** ***** ** ** **** **** you *****.

* **** ********** ** **** ****** getting ****** *** ***** ****** ** their ******* **** ***** ** **** video ** **** ***** ** ***** houses ** **** **** **** ***** security **** ***** ****** ***** ****.

** *** *** ******** *****....

(3)
JH
John Honovich
Aug 19, 2024
IPVM

*******, * *********** ******* ** *** hard ** ** ** ****** ***** systems. ** ***** ** ******* *** find * ************* ** * ***, they *** ******* **** ** ****** to *** ** ***** *******. **** conventional ******** ****** ******* ***********, *** cannot, ***** ** **** ***** ***** problems ** **** **** ** * significant ****-**** ****.

(1)
(1)
Avatar
andrew fulton
Aug 19, 2024
AFAP Consultancy

**** * *** *** ** *** we **** *** ***** ******** ****** in *** ****'* ***** ***** **** out '***' ******* ** *** ******** releases , ************* *** ****** ******** has **** **** ** ***** ***** intelligent ******* ** *** ****.

********* **** ****** *********** *** ******* can ***** * *** ** ******, and *** ** ****** * **** more ********* ******.

(2)
Avatar
Charles Baker
Aug 19, 2024

>>>****** ******* *** ******* ************ **** hacking ***'* **** ** ****, **** become **** ******* ** *** ***** available ******** ** *******, *** ***** will ****** ** ***-***-**** **** ***** who **** "**** * ***" ** defeat **** *** **** ****** *** massively *********** *********** ** ********** *** reader.

****,

* ***** **** ***** ******** ********* a ****-**** ****. *** * *********** and ********* ****some ********* **** * **** ** ****** that ***** ******** ** ** ****** as ******** ** *** *****. *** as * ****** *****, ** **** in * ***** ***** ***** ** a *****-****** ****** ** **** *****-*** and *****-*** ******* ** ***** **********.....*** that ** *** *** ****** ***** of *******.

** ***** **** **** **** ******* who ** *** **** ***** *** risk *********** ** *** **** ***** and *******, ***** ***** ******* ****, want *** *** ******* ** *** for *** **** ****** ******** ********** *** ****. ******** ** ***, ***** *** more ** *** ****** ******** **** the ******.

** * *******, ** ****** *** clients ** *** ******* ********* ********* (excluding ****, ***, ***...) *** ******* with **** ** ****** ** *** level ** ******** **** **** ***** need ***** **** ***** ******. * suspect **** **** ********* *** **** integrators ****** *** **** ********.

***, ** *** *** * ******* that **** "****" ** *** ***** tactics. ** ****** ** ***** ** have *** **** **** ***** ** a ****** ******** ** ***** ***** hacked/duplicated. ****** **** *** ** ********** an ******** ***** ** *** ****'* card ****** ** ******* ****'* ********, and **** *** ******* ** *** literally * ********* **** **** ***. That's * ********* *******, ****** ** the ******* *****.

***** **** *** ******* ********** **** race **** *** **** ******** *** years, *** ***** **** *** *&* effort ******* ** **** ****** ******* in *** "***********" **********?

** *** ***** ******* * ****** card ** * ******, **** ** verified *** ************** ***** * ********** new ****** ****# ** *** **** it ** *********, *** ***** **** have * ******** ****** **** #..........*******, which ***** ********* ** ***** ** hack..... **** * *******.........

(1)
(1)
MK
Mert Karakaya
Aug 16, 2024
IPVMU Certified

** **** ***** ***'* ********** ******** on ***** *** *******:

***'* ********** ********:

** ****** **** * ****** ********* away **** ******** ****, ** *** waiving ***** *** **** *** *** first ** ****** *** *** ******** who ****** ** **********. *** *** Elite ******* ******** ***-**** ********* **** a ****** ************** *** ** ******** their ******** ********. ** ****** ** the *** ***** *******, ***** *** first ***** ** ******** * ******* form *** *** **** ********* ** an ********** ************** ** **** **** through *** ******* ** ****** ***** unique *** ******** *********. *** ******* utilizes ********** *** **********, ********* ****** control ****, ************, ** ***********/******* *** place ***** ****** ******** **** ***. This ******* ******* **** *** *** user *** ******* **** ***** ****** control ********* **** ****** ** ***** keys. *** **** *** **** * size ********** ** *********** ** *** HID ***** ******* *** *** ******* any ******** **** ********* *** ***** through *** ********** ********. *** ******* based ** ******* **** ***** ** an ********* ** ******** *********. ** such, ** ********* *** *** **** interested ** *** ******* ** ******* their *** ************** *** * ************ consultation.

(1)