Impact
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential’s static 7‑byte UID stored on an NTAG212 NFC chip. The UID is transmitted in clear text on every read and is not intended to be secret or to authenticate the holder. Validating only the UID is identification, not authentication, and the system offers no challenge‑response capability to resist cloning. Consequently, an attacker can simply copy the UID from an authorized NFC tag and gain physical access to the asset.
Affected Systems
Norwegian Cruise Line’s door access control hardware that employs NTAG212 NFC chips for entry. No specific version or firmware information is provided in the report; the affected assets are those that use the described UID‑only authentication method.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity assessment, while the EPSS score is not available, leaving the exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation. The likely attack vector is physical proximity to the NFC tag to read the UID or to clone the tag, enabling an attacker to bypass the door lock without prior credential compromise. Given the absence of authentication, any reader with sufficient range could simply copy the UID, making the risk significant for physical security controls.
OpenCVE Enrichment