Project Subscriptions
No data.
No advisories yet.
Solution
The vendor provides a patch which should be installed immediately. Specific fixed version information was not provided. Affected parties should contact the vendor to request the update.
Workaround
Restrict filesystem and backup access to the SafeController application installation directory and related configuration files. Ensure that application binaries, licence.whs, and configuration files are not exposed through web-accessible paths or document download functionality. Rotate affected keys and secrets where possible after installing the vendor-provided patch. These measures should only be treated as interim risk reduction; the vendor-provided patch should be installed.
Mon, 15 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker with access to the application files can reverse engineer the DLL and recover the hard-coded cryptographic key. This key can be used to decrypt the licence.whs file, which contains sensitive information about the licensing party and a second key that can be used to decrypt other configuration files. | |
| Title | Hard-coded cryptographic key in Wertheim SafeController Software allows decryption of sensitive configuration data | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2026-06-15T10:05:13.770Z
Reserved: 2026-03-25T10:46:45.516Z
Link: CVE-2026-34029
Updated: 2026-06-15T12:27:07.648Z
Status : Received
Published: 2026-06-15T12:16:25.500
Modified: 2026-06-15T12:16:25.500
Link: CVE-2026-34029
No data.
OpenCVE Enrichment
No data.