Executive brief
Wertheim SafeController is a management platform used by banks and financial institutions to control physical safe deposit boxes and vault rooms. A security flaw allows an authorized user to bypass location-based security restrictions by spoofing their network address. This means a staff member who is only supposed to access the system from a specific branch office could potentially log in and manage sensitive vault data from an unauthorized or remote location.
Technical details
The Wertheim SafeController Software (AssemblyVersion 6.15.8328.28014) fails to properly validate the source of client IP addresses during the login process. While the application intends to restrict access based on the IP address associated with a specific branch, it incorrectly trusts the 'X-Forwarded-For' HTTP header to determine the client's location. An attacker with valid low-privileged branch credentials can provide a spoofed IP address in this header to bypass geographic or network-based access controls. This allows the attacker to establish an authenticated session from an unauthorized network location. A patch is reportedly available from the vendor, though specific version numbers for the fix were not disclosed in the advisory.
Affected products
- Wertheim SafeController Software AssemblyVersion 6.15.8328.28014
Timeline
- 2023-04-03: disclosed: Vulnerability discovered by SEC Consult Vulnerability Lab
- 2026-06-15: advisory: Public advisory and CVE assignment