{"vuid":"VU#676317","idnumber":"676317","name":"Norwegian Cruise Line door access controller contains an improper authentication vulnerability","keywords":null,"overview":"### Overview\r\nDoor access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers.\r\n\r\n### Description\r\nNorwegian Cruise Line is a global cruise company that operates a modern fleet sailing to destinations worldwide. As described in **CVE-2026-75907**, the affected card reader authenticates NFC credentials only by checking their static 7-byte UID.  A UID is not a secret and does not support cryptographic challenge‑response operations, so it cannot serve as a reliable authentication factor. Although the keycard's NTAG212 tag contains a memory block with a printed serial number and a value resembling a signature, the reader does not inspect this data during the access-control process. Validation based solely on UID constitutes identification rather than authentication. Because the credential performs no cryptographic exchange and offers no defense against cloning, any device capable of replaying or emulating UIDs can reproduce a functioning keycard.\r\n\r\n### Impact\r\nAn attacker with brief physical proximity to a valid keycard can use an RFID reader to capture the UID without interacting with or altering the card. Once obtained, this UID can be copied to an inexpensive UID‑writable card to create a permanent duplicate credential. The access control readers will accept these forgeries as genuine, granting entry. Depending on logging configuration, the unauthorized entry may be indistinguishable from legitimate use. Because unauthorized access to restricted areas on a cruise vessel can have direct safety implications, this vulnerability presents a significant security risk to both internal operations and guest safety. \r\n\r\n### Solution\r\nUnfortunately, we were unable to reach the vendor to coordinate this vulnerability. Users are encouraged to employ the following methods to help reduce the risk of RFID cloning:\r\n* RFID‑blocking wallets and shielded card-holder sleeves prevent unauthorized scans.\r\n* Placing aluminum foil on both sides of your RFID card can help limit signal transmission by creating a basic Faraday shield.\r\n* When using or storing your card, try to keep a distance of at least 12 inches from other people or devices. Cards operating at 13.56 MHz are usually read at an approximate distance of 2–5 cm (1–2 inches).\r\n\r\n### Acknowledgements\r\nThank you to Mark Linton for reporting this vulnerability. This document was written by Bob Kemerer.","clean_desc":null,"impact":null,"resolution":null,"workarounds":null,"sysaffected":null,"thanks":null,"author":null,"public":["https://www.nxp.com/products/NTAG210_NTAG212"],"cveids":["CVE-2026-75907"],"certadvisory":null,"uscerttechnicalalert":null,"datecreated":"2026-09-24T15:44:22.267806Z","publicdate":"2026-09-24T15:44:22.140615Z","datefirstpublished":"2026-09-24T15:44:22.280540Z","dateupdated":"2026-09-24T15:44:22.140611Z","revision":1,"vrda_d1_directreport":null,"vrda_d1_population":null,"vrda_d1_impact":null,"cam_widelyknown":null,"cam_exploitation":null,"cam_internetinfrastructure":null,"cam_population":null,"cam_impact":null,"cam_easeofexploitation":null,"cam_attackeraccessrequired":null,"cam_scorecurrent":null,"cam_scorecurrentwidelyknown":null,"cam_scorecurrentwidelyknownexploited":null,"ipprotocol":null,"cvss_accessvector":null,"cvss_accesscomplexity":null,"cvss_authentication":null,"cvss_confidentialityimpact":null,"cvss_integrityimpact":null,"cvss_availabilityimpact":null,"cvss_exploitablity":null,"cvss_remediationlevel":null,"cvss_reportconfidence":null,"cvss_collateraldamagepotential":null,"cvss_targetdistribution":null,"cvss_securityrequirementscr":null,"cvss_securityrequirementsir":null,"cvss_securityrequirementsar":null,"cvss_basescore":null,"cvss_basevector":null,"cvss_temporalscore":null,"cvss_environmentalscore":null,"cvss_environmentalvector":null,"metric":null,"vulnote":252}