"Severely Impacted" Mercury Security 2020 Leap Year Firmware Issue
One of the largest access controller manufacturers has a big problem: February 29th.
Mercury Security, owned by HID, is alerting partners of the problem that will have a severe impact caused by not being able to handle 2020's upcoming 'Leap Day' if not fixed quickly.
IPVM spoke with HID about the problem, and we share their feedback inside, including:
- An Overview Of Mercury's Severe Leap Year Date Issue
- Which Mercury Security Intelligent Controllers Are Impacted
- Mercury's Instructions For Fixing The Problem
- Which Access 'OEM Partners' Use Mercury Hardware
- How To Quickly Check If Equipment Is Vulnerable
- Do Dealers Plan To Eat Service Costs To Fix?
'Severely ********' ******** **** **** *****
**** ********* *** ******* ** * time/date ****** ***** **** *** ******** hits ******** ****, ******** ***** ** 'Leap ***':
** *********** *********** **** *** ******** handle **** **** **** ************. ***** February ****, ****, **** ***, *** intelligent ********** **** ****** **** *** date ***********.
*** ******* **** *** *****, ** left **********, **** **** '******* ******' on *** ****** ******* ***** ******* LP ***********.
** ******** ** ****, ******* ********* current ******** ** *** *******'* ******, and **** *** ******* ** ** the ******* ** ********* ********:
** *** ******* **** ** ***** was ********** ** *** ********* ******** firmware ******* (**.**.*) **** **** ** the ** *********** ***********.
***** **** ** * ****** *****, in **** ****** ***, ** ** fortunate **** ***** *** ***** ***, giving ** **** ** ******* ** and ****** *** ********/********* *** *** discovered ***** *** ****.
OEMs **** ***/******** ******
*** ******** ******* ******* **** **** to ** ******* *** *** ** firmware ******** **** *** ********** *** partner.
******* ***** **** **** *********** ******** has **** **** ** *** ******** who *** ********* *** ************ *** firmware ** *******:
****** *** ******** ** *********** *********** to ******** ******* *.**.*.****.
* *** *** *********** *** ****** last **** **** *** ******** ****** been ******** ** *** *** ******** for **** *** ************.
Recommend '*********' *******
***** *** ******* **** *** ***** until ******** ****, ******* ******** ******** that ******* ****** ****** ***, ** advance ** '**** ***':
** *** ****** ****all ** *********** ** ******* *********** to reduce any risk. [Emphasis Added]
LP *********** *********** ********
*** *********** *********** ******** *********, *** physical ***** ** *** ******* ***** distinguishes *** '**' ****** **** *******, unaffected ******.
** *** ******* ****** *** ***, then **** *** '**' *** **** need ** ** ********. *******, ** the ****** *** *****, **** *** older *** ********** '**' ****** ***********.
******* ************ ***** *** ******** ****** as '******, ******, ******, *** ****** Intelligent ***********'.
Legacy ****, *** *** */*, *******, *** ** ****** *** ********
*******, *** *** ******* ******** *** impacted, ********* ** *********** ******** (**********) in '******' ******** ************* ****, *** company's ****-**** '******' ***********, *** ******** ********** '********' */* *******:
** *********** *********** **** *** ******** in “******” **** *** *** ********. Additionally, ** ****** ***********, ****** ******** (M5, **, *** **) *** ****** controllers **** ** *** *** ****** are *** ******** ** **** *****.
Over ****** ****** ****** ********
******* ******** ** ********* **** * large ******* ** *** ****** ******* market, **** ** ****** ******.
***** ******* ** ***** ****** ******* multiple *** ***** ********** *******, ** any ** ****** *********** *** **** even ** * '*****' *********** ** multiple *****, *** ******** *** ****** by *** ******* ***********.
*** ****** ***** ***** ***** ***** common ******* ********, ******** *** **** may *** ** *************:
Two ******* ** ******** ******
** ***** ** ****** *** ****** firmware *******, ***** ******** ********** ***** to ** ********.
******* ******** ***** *** *** ******* of ************ *** *** ******:
***** *** *** **** ** ****** panel ********:
- ****** **** **** *** **** ********.
- ******* **** *** ***** *******.
*******, *** *** ******** ******* *********** are ****** ** ** ******** **********, and * *********** ****** ** ******** updates *** ****** ** ** **** onsite, ********* ******* '**** ******' ** customer ********* ** ****** *** ***.
Poll: ** **** ******** *******?
*********** *** ******** **** ** ******* impacted *********, *** ********** ******* *************, and *** ****** **** ** ****** equipment **** ** *** ******** **********, the **** ** *******'* '**** ****' problem ***** ** *********** *** **** dealers ** *******.
***********, ** *** **** ** **** your ********* * ******* **** ** do *** ****** ** ** ** free?
****:
**** ****** ** ********, *** *** only ******* * **** ******** ** fairly ******* *** ** *** *** been * ******** ***** ****. *** other ******** * **** *** ** older ** ***** ***********. * **** not ** *********. ****** ** *** company *** **** **** ******* *** I ******* **** **** **** ** invoice. **** *** *******-***** ******* ****** firmware ******** ** ***** ** ** option. ** **** * ****** ***** integrator, **** ***** ** ***** ******* each **** ** ****** * **** firmware *******.
******** *** **, ***'* ** ****** upgrades ** * ******. ******* **** came **** ****** ******** ** * Friday...
******** *** **, ***'* ** ****** upgrades ** * ******. ******* **** came **** ****** ******** ** * Friday...
******* **** ******, **** **** ****, already.
*** *** ** ** *** *********** of *********. ***** ***** ** ********* job ** ******, ****** *** **** to **** **** ******** *** ******** sunday
* *** **** *** ** ** Identiv **** **** * ****** (**** we************* **) **** ** ***** ******* new ******** ** ******** ******* ** Fridays ******.
***'** *******.
***** *********** *****. ** **** ***** Lenel ****'* ******** **** *** **** yet *** ********* **** **** ****.
******. * ****** ******* **, *** individual ******* ************* *** ********* ***, like **** ******* **** ***:
**** ** *** **** ****** ***** on ** **** ** *** *****. Where ** *** **** **** ** installed *** ** *** *** * series ***********. ** **** ********* ****** to ******** ********, ******, ******** ******** almost ***** ** *** ** ******** since *** ****** ** ** **** downtime ** ********.
**** ***** **** ***'* * *** deal *** ***** *** **** **** this **** **. **** *** ** done ******** *** ****** ***'*.
**** ** ***** ** **** **** strategic ******** **** ** *** *******. Good **** ** ** ****** *********** in ************ **** ****.
**** ** ***** ** **** **** strategic ******** **** ** *** *******.
**** ****** *** **** ;)
******* ******** ******** *******'* ******* * database ********. **** *** ** *** software ********, *** ** ** *** a *********. *** ****** ******* **** the ******** ****** ** ********.
** *** ***** ** *** ***** know **** *** ****** ** **** you **** **** ** **. ** always **** ******* **** ***** *** prepare *** *** ***** *** **** for *** ****.
* *** **** *** *** * series *********** **** ** ******** ** be ****** *** ** **** ********** you ***** ****. *** ****** ******** is **** **** ******** ***** **** this ******.
**** ************* **** **** ****** **** about *** ************ ** **** ** possible **** ***** *****. *** ******** here: ******* ** ******* ***** ******** to ********* ********* **** *****. ** you *** * ******* ******* ****** this ****** ** ****** *** ******* unless ********* ****** ** *** *-****** boards.
* *** **** ** **** ***. It’s ******* *** ***** * ***’* signup *** ********* ***** ** ****** birthday!
**** *****: ***** ***** *** ** 2020.
***** ***** *******'* ****.
******* ****** ** ****:
******* ** **** ********* ***** *** Partners **** *** *****. *** *** potential *** ***** *** ******* **** update ******* ******** ********* **** **** significant ****** *** **** ** ***** Access ******* ***** . **, ** a ******** ******* ******** **** ********* any ******** ******* ******** *** ****'* current *** *******, *******'* ******** ** that *** ****'* ***** ** *** any *******. **'* * ****** **** decision ** ***** **** *** *** protecting *** *** ***** **** ******* Hardware ******** ******.
*** *** * ******* ******* *** now ** ****** **? * ****'* think **** *** **** ** ****** for * ************. ** ***** **** once *** **** ****** ****** ******** it's ****** **** ** ******* ******** for *** **** ****** *** *******.
*** ***** ******* ***** ** ***-***** were ********* ** *** ******** *** now *** ***.
*** *******, ** **** ******* ****** maintenance ***** *** ******/********* ***** ** a ****** *** **** *** *** system ******* **-**** ******* ****** *******.
*******, ** ***** ****** ** * small ****** ** ***** ***** *** new ** ****** ***, *** ***** impacted ***** ***** **** ******* ********* with ** ***** ************ **** ******* to *** ***-****.
**** ** **** **** *** **** affects ** ****** ***********, ***** **** been *** *** * ********** ***** timeline. ***** *****'* ****** ** **** been *** ******** **** **** **** in **** ****, ** **** *******'* really ** * *******.
******* ********:
******* ** ********* ** *** *** OEMs **** **** **** *** ******** products ***** **** **** ** *** start ** ***** ** **** ****. All ** ***** ********* *** ***** current ****.
** [ $$******* == '**-**-****' ] ; ****
******* '**-**-****'
**
;)
** *****'* ***** **** ******* ***** affects * **** ******* ****** ** customers. ** ***** *** *******'* ******** not ** ******* ***** *** ******** with ******** ******* **** *** ******** is *** * **** ******** ******** nor ** ** ****** ** *****'* marketplace. ****** ** ***** ******* *** Partners *** *** *** **** **** from ******* *** ***** **** * larger ******** ** **** **** ** issue ** *** ******.
** ******* ***** **** **** *******, why ***** * ******* ******** ******* even ****** **? ** **** ***'* use ******* **** **** ***'* **** mercury ******** ** *** *****?
**** *****, ***********, *** ******** ******'* be ***** ** ****** *********** ** non-legacy ****, ****** **** **** **** so ** ***** *** ******* ******* from ******* ** * ***'* *** why *** ***** ******* ****** ************* support ****.
**** ******* *****'* **** *** ***** for * ******** ******* ** *** computer *******. ** * ****** ** potential ***** ******** **** ***** ** on * ******* **** *** ******* & ********* ** **** ***** *** now ***** *** *** **** ****'* purchased **** ** ****** ** *** of ***** ******** **** ******* *** isn't *** *********** ** ***** ***** customers. **** ***'* * **** ******** practice. *** ***** *** **** ** a ******* **** ** ********* *********** a ****** **** ***** *** *****'* purchase ****** ******** **** **** ** their ******** *** **** * ******* agreement, *** *** *** ***** ** get *** ****** ******* ** ******** system *******? **** ********* ****** * process ** ******* ******** ******* *** patches *** ***** ******** *** ******** until **** *** *** ** ****.
***’* **** ***** ** ********* ****?
********* ;)
*'* ***** ******* * ** *** sql ****** **** ***** ** * gateway ** **** **** *******.
******* *** ****** **** ***-** ************ to ***** ******:
******* ** ***** ** ************ *** issue, ******* **** ***** '******* ****' are *** **** *********** *** ******* word ** *** *****. ** * followup ** ****, ******* ****:
- *** ************ ******* *** ***** ******* our *** ********. **** ****** ** do ***** ******* *** ******* *** fix.
- *** **** *** **** *** **** ones *** **** ***** ****** *******. While ** ********* *** ******* ** be ********** ** *** ******, **** is *** * ******** ** *** industry.
**** ***** ** ******* '** *** ****** ** ** ** proactive ** ******** ** *** *** word ***.'
** **** **** **** * *** for * ***** ******* ***** *** to ****** *****'* ******* ****:
**'* ********* * **** ***** *** will ****, ** *****, ******** ** making *** **** *** **** ***** access *******.
*** ***'* **** * ***** ** have * *********** ****** ********. ** was ****** "******* ******", **** ** the ***...
*** **** ** ***** **** ********* have **** ****** **********? ** **** common?
*** ***'* **** * ***** ** have * *********** ****** ********. ** was ****** "******* ******", **** ** the ***...
"******* ******" ****** **** **** *** cloud.
** **** ****'* **** *** ****, back ** *** ***.
******* ****** *** **** ****** ****** came **** ******* **** ****, ***. that's *** *** **** ** * cloud ********.
**** **'* * *** ********** **** the ******* *** ******* ** ** different ***** **** ********* *******. **** info ******** *** ***** ******* ****'* exist ***** **** ***** ** **** was ****** *******...
**** **** ******** *** ***** ******* didn't ***** ***** **** ***** ** what *** ****** *******...
*** **** ******* ******** ** ***** OEM ******** ***-*******. ********** ******** ******* the ********** '****** *** ********' ******** to ******* ** ***** *** ******** schedule.
**** ** ***** ******* *** ***-******** tested *** ******** *** ***. ***** me * ***** ****!
* ******** **** *** ******** * global ******** ******* ****** ******* *** was ******** ** * ******* ***** to ***** *** ** ***** ******* update **** ******** *** ********. **** stopped **** *** ****** *** ******* and ********* *** ******* ******** **** month ****** ************ ** ****'* **** effective *** **** ****'* *** * difference.
**** **** ** **** ** ***** lot ** ***** ****** ********* ********** the ***** ** ***** *********...... ** well * ** **** ** **** be **** ** ** ****** ****** and *** ********* ****** *******
*** ****** ********* **** ** *** bench ***? ** **, **** ** what *******.
********'* **** ****, *****? ** ******* else *** ***** **** ** **** the **** ** **** ******** ** confirm **** ** *** **** ****-***** .. ********* **** ********** ***...
**’* **** * *** ***** ***** I ****** ** ***** *******, *** back **** *** ***** **** * firmware ****** **** *** ******* *** schedule **** ** ***** **** **.
***** **** **** ***’* ** *** an ***** *** ****, ****** *’* wrong.
*** **** ******* **** **** ** Lenel ********* **** *** ******* *********** versions (*** *.*) ** *** ******** hasn't **** ****** *****. *** **** from *.* ** *.* ***** **** decent ************ ** **** ** *** enterprise *********, ********** **** ***** *****-****** deployments.
*** ****** **** ******* *** ******** from *******? ***** ******** ** ***** (7.4 *** *****) ******* ** ****** mode ** *** *** ********. ***** versions ** ******* (*.* *** *****) operate ** ****** **** ** *** NOT ********. **** ***** **** *** your *** ********* *** ***'* ****** to **** ** **** ***** ****/**** Package/SUP ** ******** *** ****** ****** to ** ** ** *** **** THIS *******! ****** *** **** * customer **** *** ***** ******* ********* expire **** ******** *** *** **** up ** ****, **** ** *** an ***** ** ***.
** *** *** ******** ** '**** if *** ******** ***** ** * different ******** ** *** ******' **** is **** ********** ** **** *** here ** *******'* *******. ********** ** what ******/******** ** **, *** **** have ** ******** **** **** ** firmware **** *** ****** ****, ** this ***** ** **** ********.
******. **** **** *** ** **** do ******* ******* ** * *** version **** *** **** ** ******* firmware ********* ** *** **** ****** and *** ******** **** **** ** prepared *** ****.
***, ***** *** *** *** ******! There *** ***** ** ** **** different ********* ****, ********* ********* ************* on ****.
** ************* **** *** ******** ******* team *****'* ******* *** ***** ** legacy ****. ************, *******'* ****** ***-***** has ** ******* ** ****** ****.
**** * ******** ***********, ****'* *** the *********** **** ****.
*****, **** ** ******* **********, ******* Marketing *******, ****** ******* ** *******.
* ***** **** ** ******* *** comment ***** ******* **** ***** ******** Center ******** (*.* *** *****) ******** in ****** **** *** *** *** affected ** **** *****.This ********* ** **********.
****** ** *** ********** ******* ********* through *** ******** ***** **** *****-****** architecture, *** ** ****** **** **** genuinely ********** **** ***** ******** ** Security ****** ** ******** ************* ****. Therefore ** ****** ****** ** ** panels ** ***** ********, ***** ** 5.8 (******** ** *** ****). ** such, ******* *** ***** **** *** legacy **** ** ********* *** ******* LP ****** ** ******** ******.
** ******* ****ALL ** ****** are affected by this issue and Genetec customers must upgrade to Mercury firmware 1.29.0 regardless of the Security Center version being used. “
**** *******,
*******
*** ** ******* **** ******** ****** and ** **** ****** *** ** on *** ** ** ** *** notification.
**** ** *** **** ** ** have *** **** *******. ** *****’* matter **** ****** ** **, *** can ***** **** * **** ******** and ** ****** ***** *** *****.
*** **** ***** ** **** *** trots *** *** "*** **** * staging ******, *****?" *********. *** ** guess, ***'** * ****** **********, *** have **** ******* *** ****'** *** silos *** ****** *** ****** *** a **** ******...
* ***** ** *** *** ** should ** ***** **** ******* **** out ****** *** **** *** *******!!
******* *** **** * **** ******** to ******* ** **** *****:
******* ******** ******** ***** "***" ** bulk ****** *** **'* *** ********* more **** (*?) ** * ****. It ***** ** *********** ** **** some ******** **** ***** ***** *** have ****** *** ******...
**** ****** ** * **** **** and * **** ****** *** ***** Mercury-based *************. *** ****** ** **** about * **** *** * **** after *** ***** ******** ** ******** when ** ******* ******* ** *** same ****. ****'* ****... *** ** least ** ** *** ****-********!
** **** *** ******* ******* **** not **** **** ** *** **** affected ****** ***** *** *** **** listed *** ** *** *** ** purchased **** ** ** ** **** with ********* *** ***** ********. *** unprovoked. ** **, **** *** **********.
***** *** **** ******* *** ************ that *** ****? ***** **'* ********** and ****-******** *********.
** ** *****, *'* *** ****** a ******* ******** ****...*'* *** * manufacturer, *** * **** ** **** who *** ****...*** ** ************ ******* to *****.
****** **** ** *********'* ***-***** ****** are ********? * ******* **** ***** up **** ** ********, *** **** don't **** *********. ********* ** *********** slow **** ******* *** ***********.
********* ******* ** ** ******** *** worst-case ********..........** ** **********......
(******* ***** ****...) ********* **** ***** own ******** (****** *****?) ******* *******'* software. * ***** ***** **** *** not ***** ***** (*.*. *** ******** in *** ** ******.)
********* ****** *** *** ********. *******, Honeywell **** ***** *** ******** ********* Mercury, ** **'* ******** ********* ***** have **.
* ******* *** ******** ******** ******** update ** *** ****** ******. ** short, *** ****** ****** ******** *** our ************; *** ****** ******* ******* properly. * ****** *** ******** **** and ** ******** ** ******. ******** performed **** ******* ********, *** **** unable ** ******* *** ********. * recommend ******* *** ******* *******.
****** *** *** *****, *****. ******** has **** ** ***** **** ** and ** ******** *********** *** ******.
***** **** *******, ******** ********** *** issue. * **** **** *********** **** no ******* ******** (*** *******, ******* exit *****). *** ******* ***** **** the ******* ******** *** *** ******* properly ***** ******** ***** ** * software "***** ******". ******** ********* *** information ** *******, *** ** ** yet ***** *** *** **** *** indication **** **** ******* ******* ********. At ***** * **** *** ****-******.
[******] ***** *** *********** ****** ** an ******** *******. **** *** *** a ******* ******* *** **** **** removed.
******.
* **** ******* * * ****** controllers **** ** ** ** ************.
*** *** ******* **: *.**.* (***)
*** ************ **** ******* *** ******.
***** *'** **** ** **'* ***** on ***** ***.
**** ***** * *** *** ********** setting * *** ****** ** **** board ** * ***** ***** **** the ******* ***********. * **** ***** and ******* * **** ** **** of **** ** **** ****** ******* simpler.
** ** ** ************* **** *** advising ******** ** ** ** *.**. You ******** **** ** ****** ***'** supposed ** ** ** * (*** older) *******.
* **** ***** ** ******** ** verify *** ******* ** **** ** is *******.
*’* ******** **** * ******* * user ** **** ** *** ******... just ** ****!
** ********** ** ***** ****** **** S2 ********** ***** ** *.**.*
** ****** **** ** ***** *********, I'd ********** *** ********.
**** ** **'* ********:
** **** *.**.*. ****, ** ********* ship **** ****** ** ****** ****, which ***** ***** *** ***** **********, but ** ********* ***** ****** ****.
****** *** *** ********** **** **** our ******* **** ** ********* ** answer ***** ********* ****** **** **** of ****** **** **.
***** * **** **** *** **** shameless ****:
**** ** *********** *** * ** going ** ***** ** **** *** statement **** ** ** **** ***** to ***** **** **********.
** ** ***** ** ********* / partners, * *** *** *** ** makes ***** ****** ****** *** ********* angle ** **** ****** ***** ********* be ********* ***** *** ** ********.
*'** ******* ***** ** ***** **** your *********** ****, *** ***** ** the **** ***...********** ** **** ********.
******. **** ***** ***** *** ** gloating *****. **** ********* *** ******** that ** ******* **** ****, *** always **** :)
*** ***** * ********** ***** * mistake *** **** ******* ***'* ****** until *** ****** ** ******* *** in *** ****. ******** ***** ******** it ** *** *** ****** *** mistake ***** ********* *** ***********. * was ***** ** *** **** * months ****** ***** **** *****.
*************, **** (******** *****) ** **** making ******* ********** *** *******:
******* *** ***** ******** ******* *** going *** *****. ****** ********* *********** issues **** *** ******** ******* *******? Panels ******** *** *** ********* ***..? What ** *** ******* **** **** of * ***** ****** **** *******?
*'** **** ******** ** *** ******** systems (******** *** *******) *** *** no ****** **** ****** ***. **** to ******** ******* ** * ******* of *******, *** ****** **** **** just * ****** ** *******. *** only *** **** **** ****** *** a ***** ** *********, *** ********** takes ****** ** *** ***** ** not **** **********.
* **** **** ***** ******** ******* pretty *********, ** * ****'* ****** from ******** ********* ** *** *****.
** *** **** ***** ****** ***** and *** **** * *** ******* and ******, ***** **** ****** *** country **** ****** ** ****.
**** *******, *** ***** ***** ****.