AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-29916

MEDIUM · CVSS 5.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-03-21 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.6. See the original NVD description below for full technical details.

CVE
CVE-2024-29916
Severity
MEDIUM
CVSS
5.6
EPSS
0.32%

Original NVD Description

The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the "Unsaflok" issue. This occurs, in part, because the key derivation function relies only on a UID. This affects, for example, Saflok MT, and the Confidant, Quantum, RT, and Saffire series.