Description
The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.
Problem types
CWE-798: Use of Hard-coded Credentials
Product status
All versions, manual mitigation needed!
Credits
Clemens Stockenreitner, SEC Consult Vulnerability Lab
Werner Schober, SEC Consult Vulnerability Lab
References
r.sec-consult.com/dormakaba
r.sec-consult.com/dkexos
www.dormakabagroup.com/en/security-advisories