CVE-2025-59099
中文标题:
(暂无数据)
英文标题:
Unauthenticated Path Traversal in dormakaba access manager
漏洞描述
中文描述:
(暂无数据)
英文描述:
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| dormakaba | Access Manager 92xx-k5 | 92xx-K5: <XAMB 04.05.21 | - | - |
cpe:2.3:a:dormakaba:access_manager_92xx-k5:92xx-k5:_<xamb_04.05.21:*:*:*:*:*:*:*
|
| dormakaba | Access Manager 92xx-k7 | 92xx-K7: <BAME 04.05.16 | - | - |
cpe:2.3:a:dormakaba:access_manager_92xx-k7:92xx-k7:_<bame_04.05.16:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-59099 |
2026-01-27 03:17:06 | 2026-01-26 22:00:06 |
| NVD | nvd_CVE-2025-59099 |
2026-01-27 02:00:07 | 2026-01-26 22:00:15 |
版本与语言
安全公告
变更历史
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']