Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms

More than 20 vulnerabilities were found and patched in Dormakaba physical access control systems.

Door access control vulnerabilities

Vulnerabilities discovered by researchers in Dormakaba physical access control systems could have allowed hackers to remotely open doors at major organizations.

The security holes were discovered by experts at SEC Consult, a cybersecurity consulting firm under Atos-owned Eviden, in Dormakaba’s Exos central management software, a hardware access manager, and registration units that enable entry via a keypad, fingerprint reader, or chip card.

Several types of vulnerabilities were identified, including hardcoded credentials and encryption keys, weak passwords, lack of authentication, insecure password generation, local privilege escalation, data exposure, path traversal, and command injection issues.

The vulnerable product is mainly used by large enterprises in Europe, including industrial companies, energy providers, logistics firms, and airport operators. 

Exploitation of the flaws identified by SEC Consult researchers could have allowed threat actors to directly unlock doors, obtain access PINs, or conduct further attacks in the compromised environment. 

“A few thousand customers were potentially affected, with a small subset having high-security requirements,” Dormakaba told SecurityWeek

Advertisement. Scroll to continue reading.

In total, more than 20 vulnerabilities were discovered and reported to the vendor, which over the past year and a half has been working to release patches and hardening guidelines. 

Dormakaba has also been working with major customers to ensure that their access systems are no longer vulnerable. 

According to the vendor, “To exploit the vulnerabilities, an attacker needs prior access to the customer-specific infrastructure (network or hardware). As a result, exploitation would only be possible from within the customer’s own protected network.”

However, SEC Consult has identified a few dozen internet-exposed systems that were vulnerable and could have been targeted by hackers to open doors directly from the web. 

Dormakaba stated that it’s “not aware of any cases where the identified vulnerabilities have been exploited.”

The cybersecurity firm has published a video showing how an attacker could have exploited the vulnerabilities to open doors using specially crafted requests:

Related: Payment System Vendor Took Year+ to Patch Infinite Card Top-Up Hack: Security Firm

Related: Researcher Says Healthcare Facility’s Doors Hackable for Over a Year

Related: Organizations Slow to Protect Doors Against Hackers: Researcher

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.