Watchfire Controller Software
Summary
A critical vulnerability, CVE-2026-5846, has been identified in Watchfire Controller Software versions BC550 12.30, BC750 11.33|12.35, BC760 12.38|13.00, and BC760DC 12.39. Exploitation could allow a malicious user to deliver malicious firmware, update the controller, and gain full control.
IFF Assessment
The discovery of a critical vulnerability that allows for full control of industrial controllers poses a significant threat to operational technology environments.
Severity
The CVSS score of 5.7 reflects a medium severity, primarily due to the 'Use of Hard-coded Cryptographic Key' vulnerability. While it allows for significant compromise (full control), it may require specific conditions or access to deliver the malicious firmware.
Defender Context
This vulnerability impacts critical infrastructure sectors, including commercial facilities, manufacturing, healthcare, and financial services. Defenders should verify the versions of Watchfire Controller Software in use and apply the vendor-provided patches to disable the use of hard-coded cryptographic keys, which can lead to unauthorized firmware updates and control.