nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58311 CVE-2024-58311
HIGH
Dormakaba Saflok System 6000 Key Generation Cryptographic Weakness
Record summary
CVE-2024-58311 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Dormakaba Saflok System 6000Browse dormakaba / Dormakaba Saflok System 6000Default status: unaffected | CVE List | Version range not supplied | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSaflok - Key Derication Function ExploitExploitDB exploitby planthopper3301Not analyzed1 file
References
4Dormakaba Vendor Homepageproduct
https://www.dormakaba.com/ ExploitDB-51832exploit
https://www.exploit-db.com/exploits/51832 VulnCheck Advisory: Dormakaba Saflok System 6000 Key Generation Cryptographic WeaknessThird-party advisory
https://www.vulncheck.com/advisories/dormakaba-saflok-system-key-generation-cryptographic-weakness