Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf3f-jhfm-f446

Опубликовано: 26 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.

EPSS

Процентиль: 3%
0.00017
Низкий

8.5 High

CVSS4

Дефекты

CWE-798

Связанные уязвимости

nvd
13 дней назад

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password was valid for multiple observed firmware versions.

EPSS

Процентиль: 3%
0.00017
Низкий

8.5 High

CVSS4

Дефекты

CWE-798