Authentication Bypass for SafeLine SL6 and SL6+
Summary
| CVE | CVE-2025-4994 |
|---|---|
| State | PUBLISHED |
| Assigner | SCHUTZWERK |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-22 10:16:17 UTC |
| Updated | 2026-06-22 19:49:09 UTC |
| Description | The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration. |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002000000 probability, percentile 0.098940000 (date 2026-06-25)
Problem Types: CWE-305 | CWE-305 CWE-305 Authentication bypass by primary weakness
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423 | Secondary | 8.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SafeLine | SafeLine SL6/SL6 | affected 4.82 4.97 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.schutzwerk.com/en/blog/schutzwerk-sa-2025-001 | 23637b5d-af4c-4cf9-b8f6-deb7fd0f8423 | www.schutzwerk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: The vulnerability was discovered by Jan Hüber of SCHUTZWERK GmbH. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2025-03-28T11:00:00.000Z | Vulnerability discovered |
| CNA | 2025-04-14T10:00:00.000Z | Initial contact with vendor |
| CNA | 2025-04-16T10:00:00.000Z | Vulnerability reported to technical support of vendor |
| CNA | 2025-05-08T10:00:00.000Z | Follow-up meeting was canceled by vendor |
| CNA | 2025-05-16T10:00:00.000Z | Initial contact with CTO of vendor |
| CNA | 2025-05-28T10:00:00.000Z | Vulnerability presented to CTO of vendor |
| CNA | 2025-06-16T10:00:00.000Z | Vendor informed SCHUTZWERK that the patch was currently tested |
| CNA | 2025-07-03T10:00:00.000Z | Follow-up meeting was canceled by vendor |
| CNA | 2025-07-31T10:00:00.000Z | Follow-up meeting was requested by SCHUTZWERK |
| CNA | 2025-08-21T10:00:00.000Z | Vendor informed SCHUTZWERK that the patch was postponed |
| CNA | 2025-08-28T10:00:00.000Z | Vendor informed SCHUTZWERK that the patch was currently tested |
| CNA | 2025-12-19T11:00:00.000Z | Vendor informed SCHUTZWERK that the patch was released |
| CNA | 2025-12-19T11:00:00.000Z | Disclosure delayed for 180 days to allow patching the affected devices during scheduled maintenance windows |
| CNA | 2026-06-19T10:00:00.000Z | Advisory released by SCHUTZWERK |
Solutions
CNA: A patch is available in firmware version 4.97 and should be applied immediately. This version removes the PIN authentication feature in BLE entirely. Access to the configuration interface via Bluetooth is only possible for a brief time window following a reboot, which is similar to the current behavior when disabling "Auto Enable BLE".
Workarounds
CNA: The "Auto Enable BLE" setting should be disabled. This ensures that the BLE interface is deactivated after the initial time window, preventing wireless access to the configuration interface.