Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-662h-839m-x83f

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.

EPSS

Процентиль: 16%
0.00052
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1245

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.

EPSS

Процентиль: 16%
0.00052
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1245