Lennert Wouters

Researcher fromimec-COSIC, KU Leuven, Belgium
#3766of 53,633
68.8Total CVSS
Vulnerabilities · 11
Low
1
Medium
8
Critical
2
PT-2024-23138
5.6
2024-03-21
Dormakaba · Rt Series · CVE-2024-29916
**Name of the Vulnerable Software and Affected Versions** dormakaba Saflok system versions prior to November 2023 software update Saflok MT versions prior to November 2023 software update Confidant series versions prior to November 2023 software update Quantum series versions prior to November 2023 software update RT series versions prior to November 2023 software update Saffire series versions prior to November 2023 software update **Description** The issue allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property. This occurs because the key derivation function relies only on a `UID`. **Recommendations** For dormakaba Saflok system versions prior to November 2023 software update, update to the November 2023 software update or later. For Saflok MT versions prior to November 2023 software update, update to the November 2023 software update or later. For Confidant series versions prior to November 2023 software update, update to the November 2023 software update or later. For Quantum series versions prior to November 2023 software update, update to the November 2023 software update or later. For RT series versions prior to November 2023 software update, update to the November 2023 software update or later. For Saffire series versions prior to November 2023 software update, update to the November 2023 software update or later.