An immediate mitigation solution is available for a security vulnerability associated with both the key derivation algorithm used to generate MIFARE Classic® keys and the secondary encryption algorithm used to secure the underlaying card data. This vulnerability affects Saflok systems (System 6000™, Ambiance™, and Community™).
As soon as we were made aware of the vulnerability by a group of external security researchers, we initiated a comprehensive investigation and prioritized developing and rolling out a mitigation solution. With a mitigation solution available now, customer communication has been initiated.
We are unaware of any reported instances of this issue being exploited. Still, we strongly recommend all customers not already engaged in scheduled security upgrades address this vulnerability as soon as possible.
Learn more about your specific mitigation needs below.
A group of external security researchers notified dormakaba that they had identified a security vulnerability associated with both the key derivation algorithm used to generate MIFARE Classic® keys and the secondary encryption algorithm used to secure the underlaying card data. This vulnerability affects Saflok systems (System6000™, Ambiance™, and Community™).
dormakaba is recommending all customers not already engaged in scheduled security upgrades address this vulnerability as soon as possible by taking steps to implement the available mitigation measures.
This vulnerability relates only to Hospitality and Multifamily Housing properties that use Saflok systems (System 6000™, Ambiance™, and Community™).
If you do not use Saflok systems (System 6000™, Ambiance™, and Community™) at your properties, there is no action for you to take with respect to this matter.
Customers with Saflok systems(System6000™, Ambiance™, and Community™) are advised to implement the available mitigation measures as soon as practical. This includes updating to DESFire EV3® credentials if you are using Community.
DESFire EV3 credentials provide enhanced security over previous versions of MIFARE Plus® and MIFARE Classic®. These credentials can be used for multiple application schemes allowing for a wide variety of services on one card.
To update existing installations of Community, please work with your dormakaba sales representative or our dedicated Security Support Team to ensure compatibility of all devices in the system.
dormakaba has identified a two-part mitigation solution for this vulnerability. In many cases, the first part can be implemented almost immediately with an upgrade to DESFire EV3 credentials. The second part builds on the first solution to add a second layer of end-to-end encryption and the length of time this takes to implement will depend on the specific site details.
To update existing installations of Community, please work with your dormakaba sales representative or our dedicated Security Support Team to ensure compatibility of all devices in the system.
Phone:
1-844-461-2249
Email securitysupport@dormakaba.com
The hours of operation for the Security Support hotline are Monday-Friday, 8:30am- 7:00pm ET.
Our Security Support team is available to answer your questions about the options available for implementing the mitigation solutions.
Phone: 1-844-461-2249
Email: securitysupport@dormakaba.com
The hours of operation for the Security Support hotline are Monday-Friday, 8:30am- 7:00pm ET.
Thank you, *|FIRSTNAME|*!
We appreciate your interest in our dormakaba products. We have received your message and we will contact you as soon as possible.
Wishing you a wonderful day ahead!
Your dormakaba Security Support Team
This email was sent to
*|EMAIL|*!
from
dormakaba Americas
6161 E 75th Street
Indianapolis, IN 46250
855-365-2407
hospitalitysales.us@dormakaba.com
www.dormakaba.us