CVE-2025-59101
Unknown
Unknown - Not Provided
IP Spoofing Allows Unauthorized Access to Access Manager Interface
Publication date: 2026-01-26
Last updated on: 2026-01-26
Assigner: SEC Consult Vulnerability Lab
Description
Description
Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has once successfully logged in. As soon as an authentication request from a certain source IP is successful, the IP address is handled as authenticated. No other session information is stored. Therefore, it is possible to spoof the IP address of a logged-in user to gain access to the Access Manager web interface.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dormakaba | access_manager | to BAME_06.00 (exc) |
| dormakaba | access_manager | to XAMB_04.06.212 (exc) |
| dormakaba | access_manager | to XAMB_04.05.21 (exc) |
| dormakaba | access_manager | to BAME_04.05.16 (exc) |
| dormakaba | access_manager | to BAME_05.01.88 (exc) |
| dormakaba | access_manager | to BAME_04.07.268 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-291 | The product uses an IP address for authentication. |