Unauthenticated Path Traversal in dormakaba access manager
Vulnerability Description
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59099
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Clemens Stockenreitner, SEC Consult Vulnerability Lab
- Werner Schober, SEC Consult Vulnerability Lab
References
More from dormakaba
View All →Affected Vendor
dormakaba
View all reports →