CVE-2023-0248: Johnsoncontrols Iosmart Gen 1 Firmware
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.
Affected products
- Johnsoncontrols Iosmart Gen 1 Firmware: before 1.07.02 (fixed in 1.07.02)
Published 2023-12-14. Last modified 2026-06-17.