Subscriber Discussion

HID Mercury Potential Cybersecurity Vulnerabilities

JA
Joe Albe
Mar 11, 2022

Anyone have any further information besides the released info sent out?

Independent penetration testing of HID® Mercury™ access panels has detected potential cybersecurity vulnerabilities. Initial assessment of these vulnerabilities is that they could lead to disruption of normal panel operations. Full assessment of the potential impacts remains in process.

(2)
UI
Undisclosed Integrator #1
Mar 11, 2022

* ***'* *** ******** *** *****'* ******** ****** ****.

***** *** *** *** ****? *** that **** ** ********?

JA
Joe Albe
Mar 11, 2022

***. **** *****/**

Avatar
Brian Rhodes
Mar 11, 2022
IPVMU Certified

**'** ******* *** ** *** *** will ****** ** **** ***** ********.

Avatar
Brian Rhodes
Mar 11, 2022
IPVMU Certified

******* **** **** ** ******* **** morning. *** ***** *** *** ********* to **, *** *'* ******* ** this. *** ************* ******* ** ** on *** ** / *** ********** / '****** *' ******:

******: *** ******* ****** ***** ************* Statement *** **********

*********** *********** ******* ** ***® *******™ access ****** **** ** ******* *** detected ********* ************* ***************. *** ******* assessment ** ***** *************** ** **** they ***** **** ** ********** ** normal ***** **********. **** ********** ** the ********* ******* ******* ** *******.

******* ************* *********

******* ** *********** **** *** ******* are ******* ******* *** ********** ** investigate *** ******* *** ********* ******* of *** ********** *************** ****** *** product *********. *** ******* ******** ******** Response **** (*****) ************* ******** **** the ********* ******* **** ******* *** impacted:

· ***-*****

· ***-*****

· ***-*****

· ***-*****

· ***-****

· **-**-****

· **-**-****

· **-**-****

· **-**-****

******** ***** ****** ****** ** *** most ******* ******** ********, ********* ** LenelS2 ******* ****** *** ******* ******* Central, ** **** ** ******** ********* several ** *** ******** ******.

********** ******** ******* **** ** **** available ** *** ****** ****** ** incrementally ******* *** ********* ******. ******* will ******* ********** ************** **** ***** firmware ******** ****** *********.

*** ******* ********* ***-** *** *** Mercury ******** *.*.**

* *** ******* ** *******® *** Mercury ********, *** ********* ***-** *** Mercury ******** *.*.**, ** ********* *** download ** ******* ******* ******. ****** note **** **** **** *******, ** are ***** * ****** ** ******** that ********* ******** **** ******** ******** to ******* **** *********** ** ******* releases ** ****** ** **** ** possible.

********* ***-** *** ******* ******** *.*.** includes ******** ************* ******* *** *** X-Series ***********’ ************* *** *****. ** is ****** *********** **** *-****** *********** be ******* ** *.**.* ** **** as ******** ** ******** *** ********* for ************* **********. ******* *** ** the ******* ******* *****. *** ***** firmware ***** ** **** ***-** ****** the **** ** ******** *******.

** ****** *** ***-** ******** ******** and ******* *****, ****** ***** *****:

· *** ** ** ******* ****** at***** ******* ****** | *****

· ** ** *** ********* *******.

· **** *** ******** ****, ****** LenelS2 ********, **** ********.

· ******* **** *** ** ******* on *** ****, **** **** ***-** Firmware ******* ** * ******* ******** to **. *** ********, ** ** the ******* ****** “******* ******** ***-**”, which **** ** ****** **** *** top (***** *** ******** *****)

· ** **** *******, ****** *** download *** .*** **** ****** “********* Add-On ******* ******** *.*.**,”, ***** ******** three *****: * ****.** **** **** installation ************ *** *** **** ** files **** **** ** *********; *** associated ******* ***** *** **** ******** Add-On; *** ** *** **** **** contains *** *** ******** *****.

· **** *** *** **** ** executed, * ****** ** *** ******** files **** ** *********, *** *** firmware **** ** ********* **** *** files ******** ** *** *********.

· ****** *** ******** *** ******* Notes, ***** *** ** ***** ** this **** **** ** ******* ******, under *** ******* ******* “******* ******** Release *****,” *** ****** ******* ******* FW ******* ***** - *.*.**.

*** *** *** ********, **** *** the ******* *****:

*.**.*

New ********

****

Resolved ******

******** ** ***** ***** ****** ******* buffers ***** ** ********* *** **** to **** **** **** ***** **

*********** *********** **** **** **** *** rapid ******** (********).

Security ******** ************ (********** ******* *********)

******** **** ****** ********.

******** ******** ******** ********.

******** ** ***** ***** ** ******** command ***** ** **** ** ** intelligent **********.

******** ** ***** ***** ***** ***** be *************** ******* **** ** *********** controller.

(2)
UI
Undisclosed Integrator #1
Mar 11, 2022

**... ********** **** *** * ****** about **** ******** ****** * ***** ago.

*'* * ****** ******** ** "**** assessment ** *** ********* ******* ******* in *******." *** "******* ** *********** with *** ******* *** ******* ******* and ********** ** *********** *** ******* any ********* *******". ************* ***'* ******* make ******** ****** ***** **** **** patches ** *** **. * ****** if *** *********** ********** ** ***** to ******** *** **** *******?

*'* **** * ****** ******* *** there *** ** *** ******* *********.

JA
Joe Albe
Mar 11, 2022

*****/** *** * ******** ****** ********* for ********.

(1)
Avatar
Andre Fiset
Mar 14, 2022
FisetSC

***** *****,

****** *** ****. ****** ** ***** out ** ***-******* *** *** * timely ******** **** **** ** **** scoring * *** *****. * **** the **** **** **** *********** *** responsive.

(2)
JA
Joe Albe
Mar 11, 2022

* **** *** **** **** ** find *** ***** **** ***.

(1)
Avatar
Brian Rhodes
Mar 16, 2022
IPVMU Certified

***/******* *********, *** **** *** *** give ****** ** *** ******** *** made ** ***** **** *** ******* reaction/notification/patch ***** ** ******* ***** *** allowing **** ** ******* *** ****** response.

***'* *****:

** ******** ******* ******** ******** *** are ********* ** ********** **** **** their *********** ** *** *********** ******** security ********. ******* ** ** **** platform **** * **** ***** ** partners, **** **** *** *** *********** schedule *** ************* ************* ********. ******** will **** ** ******* *** ** will ******** ** **** ******* *** customers ** ******* *** ******* *** any ****** ******* ******* ***** ********** dealer ********.

******* ** *** ****** ******* ** what *** **** ** *** *** not ********** ******** ** (** *********** the ***** **** ******* ** *** sold ** *** ******, *** ********).

* **** ***** ******* *** * list ** ******** ******** *** ******* firmware ******** **** **** *** *** for **** ***** *** **** ****** here ** *** ********.

Avatar
Andre Fiset
Mar 16, 2022
FisetSC

***** *** *****,

** *** ******* **** *** ** our ******* **** **** ********* *** stipulated ****** *** ******** *** **** if ***** ** ******** ***** **** it ********. ** *** ******** *** firmware ****** ********* ******* *** ***** portal ** ******* ********** **.

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions