Watchfire Controller Software
Watchfire controller software contains a vulnerability in certificate handling that could allow a malicious user with administrative credentials and user interaction capability to deliver malicious firmware and gain full control of the affected controller. The vulnerability stems from improper validation of firmware signatures, permitting an attacker to bypass security checks during firmware updates. Affected models include BC550, BC750, BC760, and BC760DC controllers across multiple firmware versions. Watchfire has released security patches that disable the use of the existing certificate and require stricter validation for all future updates.
- Administrator or high-privilege credentials for the Watchfire controller
- Network access to the controller management interface
- User interaction required (administrator must approve or initiate a firmware update)
- Knowledge of or ability to bypass certificate validation mechanisms
Patching may require device reboot — plan for process interruption
/api/v1/advisories/4805037e-e6dc-4aea-8f01-ab6567810110Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.