Executive brief
Synergis Softwire is a security software component used in Streamvault surveillance appliances and Windows server deployments. A flaw in access controls allows unauthorized users to access sensitive files in the Softwire installation directory, potentially exposing credentials, configuration data, or enabling lateral movement within a security infrastructure.
Technical details
This vulnerability is an improper access control flaw affecting the Synergis Softwire installation folder on both Streamvault all-in-one appliances (SV-100E and SV-300E series) and Windows server installations. The root cause is inadequate permission checks on the installation directory, allowing users with local access to read or modify sensitive files without proper authentication. An attacker with local system access can exploit this to access protected configuration files or credentials. The vulnerability has been resolved in Synergis Softwire versions 12.0.2 and 12.2.0 or later.
Affected products
- Genetec Synergis Softwire below 12.0.2, below 12.2.0
- Genetec Streamvault SV-100E <UNKNOWN>
- Genetec Streamvault SV-300E <UNKNOWN>
Timeline
- 2026-08-28: disclosed