IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Watchfire Controller Software

MEDIUM
CVSS 5.7
Date 2026-07-30T22:56:13.953193+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-5846 5.7 medium
The affected product contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.

// Remediations (7)

Patch: Watchfire has issued patches to disable the use of the existing certificates. Users using BC760; 13.
Watchfire has issued patches to disable the use of the existing certificates. Users using BC760; 13.00 should upgrade to 14.00 SP1
Patch: Watchfire has issued patches to disable the use of the existing certificates. Users using BC760DC; 1
Watchfire has issued patches to disable the use of the existing certificates. Users using BC760DC; 12.39 should upgrade to 12.41 SP1
Patch: Watchfire has issued patches to disable the use of the existing certificates. Users using BC760; 12.
Watchfire has issued patches to disable the use of the existing certificates. Users using BC760; 12.38 should upgrade to 12.41 SP1
Patch: Watchfire has issued patches to disable the use of the existing certificates. Users using BC750; 12.
Watchfire has issued patches to disable the use of the existing certificates. Users using BC750; 12.35 should upgrade to 12.36 SP1
Patch: Watchfire has issued patches to disable the use of the existing certificates. Users using BC750; 11.
Watchfire has issued patches to disable the use of the existing certificates. Users using BC750; 11.33 should upgrade to 11.34
Patch: Watchfire has issued patches to disable the use of the existing certificates. Users using BC550; 12.
Watchfire has issued patches to disable the use of the existing certificates. Users using BC550; 12.30 should upgrade to 12.31 SP1
Mitigation: Watchfire has applied the required security patch to all affected controllers under its management.
Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.

// References