๐Ÿ” CVE Alert

CVE-2024-29916

MEDIUM 5.6
CVSS Score
5.6
EPSS Score
0.0%
EPSS Percentile
0th

The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function relies only on a UID. This affects, for example, Saflok MT, and the Confidant, Quantum, RT, and Saffire series.

Vendor n/a
Product n/a
Published Mar 21, 2024
Last Updated Oct 19, 2024
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new medium vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
unsaflok.com: https://unsaflok.com news.ycombinator.com: https://news.ycombinator.com/item?id=39779291 wired.com: https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique/ youtube.com: https://www.youtube.com/watch?v=4cx0RUV7i0s