Watchfire Controller Software

Summary

A critical vulnerability, CVE-2026-5846, has been identified in Watchfire Controller Software versions BC550 12.30, BC750 11.33|12.35, BC760 12.38|13.00, and BC760DC 12.39. Exploitation could allow a malicious user to deliver malicious firmware, update the controller, and gain full control.

IFF Assessment

FOE

The discovery of a critical vulnerability that allows for full control of industrial controllers poses a significant threat to operational technology environments.

Severity

5.7 Medium

The CVSS score of 5.7 reflects a medium severity, primarily due to the 'Use of Hard-coded Cryptographic Key' vulnerability. While it allows for significant compromise (full control), it may require specific conditions or access to deliver the malicious firmware.

Defender Context

This vulnerability impacts critical infrastructure sectors, including commercial facilities, manufacturing, healthcare, and financial services. Defenders should verify the versions of Watchfire Controller Software in use and apply the vendor-provided patches to disable the use of hard-coded cryptographic keys, which can lead to unauthorized firmware updates and control.

Read Full Story →