VYPR
Unrated severityNVD Advisory· Published Dec 4, 2023· Updated Aug 2, 2024

CVE-2023-26942

CVE-2023-26942

Description

Weak encryption in Yale IA-210 Alarm v1.0 RFID tags allows attackers to clone tags via physical proximity, compromising access control.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Weak encryption in Yale IA-210 Alarm v1.0 RFID tags allows attackers to clone tags via physical proximity, compromising access control.

Vulnerability

The Yale IA-210 Alarm v1.0 uses weak encryption mechanisms for its RFID tags, making it possible for an attacker to clone a legitimate tag. The vulnerability resides in the tag's cryptographic implementation, which does not provide sufficient protection against cloning attacks. This affects all units running firmware version 1.0. [1]

Exploitation

An attacker must be in physical proximity to the original RFID tag to capture its data. Using a compatible RFID reader, the attacker can intercept the tag's communication and extract the necessary information to create a cloned tag. No authentication or special privileges are required beyond physical access to the tag. [1]

Impact

Successful exploitation allows the attacker to create a cloned RFID tag that can be used to disarm or interact with the Yale IA-210 Alarm system as if it were the original authorized tag. This compromises the integrity of the access control system and could lead to unauthorized entry or alarm deactivation. [1]

Mitigation

As of the publication date, no official patch or firmware update has been released to address this vulnerability. The vendor has acknowledged the issue following responsible disclosure. Users should monitor for updates from Yale and consider physical security measures to protect RFID tags from unauthorized scanning. [1]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.