Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability

CERT Coordination Center Version 1 original

Imported from official source

Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers. Description Norwegian Cruise Line is a global cruise company that operates a modern fleet sailing to destinations worldwide. As described in CVE-2026-75907, the affected card reader authenticates NFC credentials only by checking their static 7-byte UID. A UID is not a secret and does not support cryptographic challenge‑response operations, so it cannot serve as a reliable authentication factor. Although the keycard's NTAG212 tag contains a memory block with a printed serial number and a value resembling a signature, the reader does not inspect this data during the access-control process. Validation based solely on UID constitutes identification rather than authentication. Because the credential performs no cryptographic exchange and offers no defense against cloning, any device capable of replaying or emulating UIDs can reproduce a functioning keycard. Impact An attacker with brief physical pro...

This version

Version
1 of 2
Recorded
September 24, 2026 16:00
Change
Initial
Content hash
1be3a1b85ee2bfa8c39907a73ec61a04
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.