The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that there are two users with hardcoded and weak passwords that can be used to access the devices via SSH. The passwords can be also guessed very easily. The password of at least one user is set to a random value after the first deployment, with the restriction that the password is only randomized if the configured date is prior to 2022. Therefore, under certain circumstances, the passwords are not randomized. For example, if the clock is never set on the device, the battery of the clock module has been changed, the Access Manager has been factory reset and has not received a time yet.
The Access Manager 92xx (K7) device runs on Linux and exposes an SSH service on port 22. Two accounts with hardcoded and easily guessable passwords were detected in the firmware. One user's password is changed to a random value after initial deployment, however randomization occurs only when the configured system date is earlier than the year 2022. If the device clock was never set, the clock module battery was replaced, the device was reset to factory settings, or has not yet received time synchronization — passwords are not randomized and remain default values.
An attacker with network access to port 22 can log into the device using known or easily guessable passwords, gaining unauthorized access to the operating system of the access control device — which may lead to takeover of physical security infrastructure.
Apply patches available from the manufacturer according to the references. It is also recommended to immediately restrict network access to port 22 (SSH) at the firewall or network segmentation level, and to verify and manually change passwords on all devices whose system clock was not properly configured or which have been reset to factory settings.
dormakaba Access Manager 92xx in hardware revision K7 with Linux-based software
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X