Executive brief
The Wertheim SafeController 5400, used to manage secure locker systems and vault rooms, contains a vulnerability in how its internal components communicate. Because the communication between the central server and the safe's hardware is not encrypted, an attacker with physical or network access to the wiring can intercept and mimic commands. This could allow an unauthorized person to silence or deactivate safe alarms, potentially facilitating a physical theft without detection.
Technical details
The Wertheim SafeController 5400 (AssemblyVersion 6.11.8130.22320) lacks cryptographic protection on the RS-485 serial communication path between the server and the microcontroller. An attacker with access to the communication medium (adjacent access) can perform a packet-sniffing attack to capture legitimate traffic. By replaying specific captured messages, such as the 'quit alarm' command, the attacker can spoof the server's identity to the microcontroller and continuously deactivate the safe's alarm system. The vendor has stated that no patch will be provided as the hardware is considered End-of-Life (EOL).
Affected products
- Wertheim SafeController 5400 AssemblyVersion 6.11.8130.22320
Timeline
- 2023-04-03: other: Vulnerability discovered by SEC Consult
- 2023-06-20: other: Initial meeting between SEC Consult and Wertheim
- 2024-03-29: other: Recheck conducted; vulnerability confirmed as not fixed
- 2024-10-10: other: Vendor confirms no fix will be provided due to EOL status and hardware limitations
- 2026-06-15: advisory: Public disclosure of vulnerability