CVE-2025-59093: Insecure Password Derivation Function for Database Administrator in dormakaba Kaba exos 9300
Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The password is derived from static random values, which are concatenated to the hostname and a random string that can be read by every user from the registry. This allows an attacker to derive the database password and get authenticated access to the central exos 9300 database as the user Exos9300Common. The user has the roles ExosDialog and ExosDialogDotNet assigned, which are able to read most tables of the database as well as update and insert into many tables.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59093?
CVE-2025-59093 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to the MSSQL server.
How do I fix CVE-2025-59093?
To mitigate CVE-2025-59093, ensure that a secure and unique password derivation function is implemented for database connections.
Who is affected by CVE-2025-59093?
CVE-2025-59093 affects instances of dormakaba Kaba exos 9300 that use a randomly generated database password for MSSQL server connections.
What are the implications of CVE-2025-59093?
The implications of CVE-2025-59093 include the risk of compromised database security, leading to potential data breaches.
When was CVE-2025-59093 disclosed?
CVE-2025-59093 was disclosed recently as part of ongoing security assessments of dormakaba systems.