CVE Feed

    Dashboard / CVE / CVE-2024-29916

    CVE-2024-29916

    The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function relies only on a UID. This affects, for example, Saflok MT, and the Confidant, Quantum, RT, and Saffire series.

    Published:Mar 21, 2024
    Last Modified:Apr 15, 2026
    EPS:Mar 21, 2024
    EPSS Score:0.00181
    CVSS Score:5.6

    Affected Products

    Vendor
    Dormakaba
    Product
    Confidant Firmware
    Vendor
    Dormakaba
    Product
    Quantum Firmware
    Vendor
    Dormakaba
    Product
    Saffire Firmware
    Vendor
    Dormakaba
    Product
    Saflok Mt Firmware
    Vendor
    Dormakaba
    Product
    Saflok Rt Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High