logo

How easily access cards can be cloned and why your PACS might be vulnerable

ID: dcdd891c-28b9-54d0-a791-1256d27fb3fd

STIX ID: report--dcdd891c-28b9-54d0-a791-1256d27fb3fd

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-12-11

Date Updated: 2026-03-24

Author: Warren Houghton

...
...

This report explains how physical access control systems (PACS) can be subverted through cloning of RFID tokens, detailing the reader–token interactions, weaknesses in legacy technologies (e.g., HID Prox, iCLASS), and the risks of default encryption keys even in modern systems (e.g., SEOS). It describes attacker methods using long-range readers and tools like Proxmark3 to capture and replicate credentials, and provides practical mitigations including enforcing custom encryption keys, securing readers/controllers/servers, and proper PACS configuration to reduce cloning risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.