PatchSiren cyber security CVE debrief
CVE-2026-34022 Wertheim GmbH CVE debrief
The Wertheim SafeController Family 65000, specifically Controller 65000 with AssemblyVersion 6.11.8130.22319, employs weak custom cryptographic algorithms with hard-coded cryptographic keys to secure communication. This vulnerability enables an adversary-in-the-middle to decrypt data traffic. Furthermore, during reassessment, it was found possible to break the encryption/decryption routine and decrypt messages without needing the encryption key. Additionally, intercepting a sufficient number of messages could reveal the encryption key.
- Vendor
- Wertheim GmbH
- Product
- Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-15
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-15
- Advisory updated
- 2026-06-15
Who should care
Users of the Wertheim SafeController Family 65000, specifically those with Controller 65000 running AssemblyVersion 6.11.8130.22319, should be aware of this vulnerability as it could allow attackers to intercept and decrypt their communication.
Technical summary
The vulnerability involves the use of weak custom cryptographic algorithms with hard-coded keys in the Wertheim SafeController Family 65000. This allows for the decryption of data traffic by an attacker in an adversary-in-the-middle position. The encryption can be broken, and messages can be decrypted without the encryption key. The encryption key can also be determined by intercepting enough messages.
Defensive priority
High
Recommended defensive actions
- Update to a version of Controller 65000 that uses secure cryptographic algorithms and practices.
- Implement secure key management practices to prevent the use of hard-coded keys.
- Use secure communication protocols that are resistant to interception and decryption by unauthorized parties.
- Monitor communication for signs of tampering or interception.
Evidence notes
Evidence suggests that the vendor, referred to as 'Unknown Vendor' with low confidence, has a product affected by this vulnerability. The canonical source for this information is noted as 'reference_domain_weak' with evidence from 'Sec Consult'.
Official resources
-
CVE-2026-34022 CVE record
CVE.org
-
CVE-2026-34022 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
551230f0-3615-47bd-b7cc-93e92e730bbf
-
Source reference
551230f0-3615-47bd-b7cc-93e92e730bbf
CVE-2026-34022 was published and modified on 2026-06-15T12:16:24.410Z.