CVE Feed

    Dashboard / CVE / CVE-2017-16241

    CVE-2017-16241

    Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door controller commands (e.g., lock, unlock, add ID card value) by sending unauthenticated requests to the affected devices via Serial over TCP/IP, as demonstrated by a Ud command.

    Published:Dec 10, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 10, 2017
    EPSS Score:0.00273
    CVSS Score:7.5

    Affected Products

    Vendor
    Amag
    Product
    En-1dbc
    Vendor
    Amag
    Product
    En-1dbc Firmware
    Vendor
    Amag
    Product
    En-2dbc
    Vendor
    Amag
    Product
    En-2dbc Firmware
    Vendor
    Amag
    Product
    Std
    Vendor
    Amag
    Product
    Std Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High