The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm.
History

Mon, 15 Jun 2026 12:00:00 +0000

Type Values Removed Values Added
Description The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm.
Title Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
Weaknesses CWE-294
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2026-06-15T10:02:09.049Z

Reserved: 2026-03-25T10:46:45.515Z

Link: CVE-2026-34021

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-15T12:16:24.230

Modified: 2026-06-15T12:16:24.230

Link: CVE-2026-34021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.