CVE-2024-58311CWE-1245

Dormakaba Saflok System 6000 Key Generation Cryptographic Weakness

High · published December 12, 2025

CVSS v4.0
8.7
EPSS
0%
Percentile
34.1
In the wild
Unconfirmed
What it is

⚡ A predictable key generation algorithm in Dormakaba Saflok System 6000 could make your access keys as easy to guess as a four-digit PIN! 🔑 Think of it like a vending machine that uses the same sequence to dispense snacks every time you enter a code. If someone learns the pattern, they can get free goodies without ever inserting a coin! With this vulnerability, an attacker could potentially derive valid access keys from merely knowing a card's unique identifier, giving them unauthorized access to secure areas. This could lead to breaches of sensitive locations, putting both physical security and personal safety at risk.

Put simply

Think of it like a vending machine that uses the same sequence to dispense snacks every time you enter a code. If someone learns the pattern, they can get free goodies without ever inserting a coin! The flaw stems from a deterministic key generation process that allows attackers to compute access keys through a straightforward mathematical transformation of a 32-bit identifier. This predictability means that anyone with knowledge of the identifier can easily generate valid access keys.

What to do

With this vulnerability, an attacker could potentially derive valid access keys from merely knowing a card's unique identifier, giving them unauthorized access to secure areas. This could lead to breaches of sensitive locations, putting both physical security and personal safety at risk. To mitigate this risk, immediately assess the version of the Dormakaba Saflok System you are using and apply any available firmware updates. Additionally, implement stricter access controls and consider rekeying existing access keys to prevent unauthorized entry. You've got this! By taking these steps, you're well on your way to safeguarding your systems! 🛡️

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00408 · 34.1th percentile
Weakness
CWE-1245 · Improper Finite State Machines (FSMs) in Hardware Logic
Published
2025-12-12T19:57Z
EPSS history
Timeline
  • 12 DEC 19:57Z
    Dormakaba Saflok System 6000 Key Generation Cryptographic Weakness
    cvelistv5