Description
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.
Problem types
CWE-1245: Improper Finite State Machines (FSMs) in Hardware Logic
Product status
Unknown
Credits
a51199deefa2c2520cea24f746d899ce
References
www.exploit-db.com/exploits/51832 (ExploitDB-51832)
www.dormakaba.com/ (Dormakaba Vendor Homepage)
www.vulncheck.com/...m-key-generation-cryptographic-weakness (VulnCheck Advisory: Dormakaba Saflok System 6000 Key Generation Cryptographic Weakness)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.