216.73.217.22

CVE-2026-34021

· Published 15/06/2026 14:16 · Modified 15/06/2026 21:05 · Author: The MITRE Corporation

Labels: CVE-2026-34021 2026-06-15551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2026-34021CWE-294

Essential information

Published
15/06/2026 14:16
Modified
15/06/2026 21:05
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CWE-294
CVSS vector

CVSS metrics

Description

The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
wertheim / safecontroller cpe:2.3:a:wertheim:safecontroller:6.11.8130.22320:*:*:*:*:*:*:*

References