The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.
Watchfire has applied the required security patch to all affected controllers under its management. Watchfire recommends users verify their controller software version and upgrade to one of the approved versions below, if they are not already on an approved patch level.
Watchfire has issued patches to disable the use of the existing certificate as follows:
- BC550 12.30: Patch to 12.31 SP1
- BC750 11.33: Patch to 11.34
- BC750 12.35: Patch to 12.36 SP1
- BC760 12.38: Patch to 12.41 SP1
- BC760 13.00: Patch to 14.00 SP1
- BC760DC 12.39: Patch to 12.41 SP1