CVE-2025-59101: Insufficient Session Management in dormakaba access manager
Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has once successfully logged in. As soon as an authentication request from a certain source IP is successful, the IP address is handled as authenticated. No other session information is stored. Therefore, it is possible to spoof the IP address of a logged-in user to gain access to the Access Manager web interface.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59101?
CVE-2025-59101 has been classified as a high severity vulnerability due to insufficient session management.
How do I fix CVE-2025-59101?
To mitigate CVE-2025-59101, it is recommended to implement proper session management controls and authentication mechanisms.
What systems are affected by CVE-2025-59101?
CVE-2025-59101 affects the dormakaba Access Manager software.
Can CVE-2025-59101 be exploited remotely?
Yes, CVE-2025-59101 can be exploited remotely through authenticated sessions associated with IP address verification.
What are the potential impacts of CVE-2025-59101?
Exploitation of CVE-2025-59101 may lead to unauthorized access to sensitive information or systems due to compromised session management.