Hard-coded Cryptographic Key in Watchfire Signs Controllers
Summary
| CVE | CVE-2026-5846 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-30 22:16:55 UTC |
| Updated | 2026-07-31 16:17:08 UTC |
| Description | The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore. |
Risk And Classification
Primary CVSS: v4.0 7.6 HIGH from [email protected]
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001630000 probability, percentile 0.059290000 (date 2026-08-04)
Problem Types: CWE-321 | CWE-321 CWE-321 Use of hard-coded cryptographic key
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.6 | HIGH | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 7.6 | HIGH | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 5.7 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 5.7 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Watchfire | BC550 | affected 12.30 | Not specified |
| CNA | Watchfire | BC550 | unaffected 12.31 SP1 | Not specified |
| CNA | Watchfire | BC750 | affected 11.33 | Not specified |
| CNA | Watchfire | BC750 | unaffected 11.34 | Not specified |
| CNA | Watchfire | BC750 | affected 12.35 | Not specified |
| CNA | Watchfire | BC750 | unaffected 12.36 SP1 | Not specified |
| CNA | Watchfire | BC760 | affected 12.38 | Not specified |
| CNA | Watchfire | BC760 | unaffected 12.41 SP1 | Not specified |
| CNA | Watchfire | BC760 | affected 13.00 | Not specified |
| CNA | Watchfire | BC760 | unaffected 14.00 SP1 | Not specified |
| CNA | Watchfire | BC760DC | affected 12.39 | Not specified |
| CNA | Watchfire | BC760DC | unaffected 12.41 SP1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-26-211-09 | [email protected] | www.cisa.gov | |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-21... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: James Tilson reported the vulnerability to CISA (en)
Additional Advisory Data
Solutions
CNA: Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level. Watchfire has issued patches to disable the use of the existing certificate as follows: * BC550 12.30: Patch to 12.31 SP1 * BC750 11.33: Patch to 11.34 * BC750 12.35: Patch to 12.36 SP1 * BC760 12.38: Patch to 12.41 SP1 * BC760 13.00: Patch to 14.00 SP1 * BC760DC 12.39: Patch to 12.41 SP1