Executive brief
Wertheim SafeController is a software suite used by banks and financial institutions to manage safe deposit boxes and vault rooms. A security flaw exists where sensitive encryption keys are permanently embedded within the software's code. An attacker with access to the system's files could extract these keys to decrypt license information and configuration files, potentially exposing sensitive customer or operational data.
Technical details
A hard-coded cryptographic key was identified within the SafeSystem.Infrastructure.Security.dll component of Wertheim SafeController Software (AssemblyVersion 6.15.8328.28014). An attacker with local access to the application's installation directory can reverse engineer the DLL to recover this static key. This key is used to decrypt the 'licence.whs' file, which contains sensitive licensing party information and a secondary key used for decrypting other system configuration files. This vulnerability (CWE-321) can be leveraged alongside other flaws in the product to facilitate a broader compromise of the vault management system. A patch is available from the vendor, though specific version numbers for the fix were not disclosed.
Affected products
- Wertheim SafeController Software for VAULT ROOMS AssemblyVersion 6.15.8328.28014
Timeline
- 2023-04-03: disclosed: Vulnerability discovered by SEC Consult Vulnerability Lab
- 2026-06-15: advisory: CVE published and NVD record created