Kaba E-plex System Authentication Bypass Vulnerabilities
BID:49054
Info
Kaba E-plex System Authentication Bypass Vulnerabilities
| Bugtraq ID: | 49054 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 05 2011 12:00AM |
| Updated: | Aug 05 2011 12:00AM |
| Credit: | Marc Weber Tobias |
| Vulnerable: |
Kaba E-plex 5800 Kaba E-plex 5000 |
| Not Vulnerable: | |
Discussion
Kaba E-plex System Authentication Bypass Vulnerabilities
Kaba E-plex devices are prone to multiple authentication-bypass vulnerabilities.
An attacker with physical access to an affected device can bypass the locking mechanism.
The following models are affected:
E-plex 5800
E-plex 5000
Kaba E-plex devices are prone to multiple authentication-bypass vulnerabilities.
An attacker with physical access to an affected device can bypass the locking mechanism.
The following models are affected:
E-plex 5800
E-plex 5000
Exploit / POC
Kaba E-plex System Authentication Bypass Vulnerabilities
To exploit this issue, attackers require physical access to a vulnerable device.
To exploit this issue, attackers require physical access to a vulnerable device.
Solution / Fix
Kaba E-plex System Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Kaba E-plex System Authentication Bypass Vulnerabilities
References:
References:
- Defcon Lockpickers Open Card-And-Code Government Locks In Seconds (2011 Forbes.com)
- E-plex Homepage (Kaba)