CVE-2025-59106
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.
Affected (6)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before bame_06.00 |
| Running on/with | Platform Versions |
|---|---|
Dormakabagroup Dormakaba Access Manager 9200 K7 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before bame_06.00 |
| Running on/with | Platform Versions |
|---|---|
Dormakabagroup Dormakaba Access Manager 9230 K7 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before bame_06.00 |
| Running on/with | Platform Versions |
|---|---|
Dormakabagroup Dormakaba Access Manager 9290 K7 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dormakabagroup Dormakaba Access Manager 9200 K5 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dormakabagroup Dormakaba Access Manager 9230 K5 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dormakabagroup Dormakaba Access Manager 9290 K5 | All versions |
References (3)
Source: 551230f0-3615-47bd-b7cc-93e92e730bbf
Vendor Advisory
Timeline
No history available yet.