CVE-2024-58311: Dormakaba Saflok System 6000 Key Generation Cryptographic Weakness
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58311?
CVE-2024-58311 is classified as a high-severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2024-58311?
To fix CVE-2024-58311, update your Dormakaba Saflok System 6000 to a version that addresses the predictable key generation vulnerability.
What are the potential impacts of CVE-2024-58311?
The impact of CVE-2024-58311 includes unauthorized access to secure areas by exploiting predictable access keys derived from the unique identifier.
Is CVE-2024-58311 easy to exploit?
Yes, CVE-2024-58311 can be easily exploited by attackers with knowledge of the deterministic key generation process.
Who is affected by CVE-2024-58311?
Organizations using the Dormakaba Saflok System 6000 are affected by CVE-2024-58311 due to the vulnerability in the key generation algorithm.