vendor:
Saflok
by:
a51199deefa2c2520cea24f746d899ce
6.1
CVSS
HIGH
Weakness in Key Derivation Function
Cryptographic Issues
CWE
Product Name: Saflok
Affected Version From: System 6000
Affected Version To: System 6000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Dormakaba Saflok cards
2023
Saflok KDF Vulnerability
The Saflok KDF vulnerability allows an attacker to derive keys by exploiting a weakness in the key derivation function. This can lead to unauthorized access and compromise of the system. This vulnerability does not have a CVE assigned yet.
Mitigation:
To mitigate this vulnerability, it is recommended to update the key derivation function algorithm to a more secure and robust one. Regularly updating the system and implementing strong access controls can also help prevent unauthorized access.