"Severely Impacted" Mercury Security 2020 Leap Year Firmware Issue

By Brian Rhodes, Published Jan 17, 2020, 09:27am EST

One of the largest access controller manufacturers has a big problem: February 29th.

Mercury Security, owned by HID, is alerting partners of the problem that will have a severe impact caused by not being able to handle 2020's upcoming 'Leap Day' if not fixed quickly.

IPVM spoke with HID about the problem, and we share their feedback inside, including:

  • An Overview Of Mercury's Severe Leap Year Date Issue
  • Which Mercury Security Intelligent Controllers Are Impacted
  • Mercury's Instructions For Fixing The Problem
  • Which Access 'OEM Partners' Use Mercury Hardware
  • How To Quickly Check If Equipment Is Vulnerable
  • Do Dealers Plan To Eat Service Costs To Fix?

'Severely ********' ******** **** **** *****

*** **** * ****** to *******:

**** ********* *** ******* as * ****/**** ****** issue **** *** ******** hits ******** ****, ******** known ** '**** ***':

** *********** *********** **** not ******** ****** **** year **** ************. ***** February ****, ****, **** Day, *** *********** ********** will ****** **** *** date ***********.

*** ******* **** *** issue, ** **** **********, will **** '******* ******' on *** ****** ******* using ******* ** ***********.

** ******** ** ****, Mercury ********* ******* ******** is *** *******'* ******, and **** *** ******* is ** *** ******* of ********* ********:

** *** ******* **** an ***** *** ********** in *** ********* ******** firmware ******* (**.**.*) **** runs ** *** ** Intelligent ***********.

***** **** ** * vexing *****, ** **** menial ***, ** ** fortunate **** ***** *** found ***, ****** ** time ** ******* ** and ****** *** ********/********* and *** ********** ***** the ****.

OEMs **** ***/******** ******

*** ******** ******* ******* will **** ** ** updated *** *** ** firmware ******** **** *** respective *** *******.

******* ***** **** **** replacement ******** *** **** sent ** *** ******** who *** ********* *** distributing *** ******** ** dealers:

****** *** ******** ** intelligent *********** ** ******** version *.**.*.****.

* *** *** *********** and ****** **** **** with *** ******** ****** been ******** ** *** OEM ******** *** **** and ************.

Recommend '*********' *******

***** *** ******* **** not ***** ***** ******** 29th, ******* ******** ******** that ******* ****** ****** now, ** ******* ** 'Leap ***':

** *** ****** ****all ** *********** ** ******* *********** to reduce any risk. [Emphasis Added]

LP *********** *********** ********

*** *********** *********** ******** equipment, *** ******** ***** of *** ******* ***** distinguishes *** '**' ****** from *******, ********** ******.

** *** ******* ****** are ***, **** **** are '**' *** **** need ** ** ********. However, ** *** ****** are *****, **** *** older *** ********** '**' series ***********.

******* ************ ***** *** impacted ****** ** '******, LP1502, ******, *** ****** Intelligent ***********'.

Legacy ****, *** *** */*, *******, *** ** ****** *** ********

*******, *** *** ******* products *** ********, ********* LP *********** ******** (**********) in '******' ******** ************* mode, *** *******'* ****-**** 'Bridge' ***********, *** ******** ********** '********' */* modules:

** *********** *********** **** are ******** ** “******” mode *** *** ********. Additionally, ** ****** ***********, bridge ******** (**, **, and **) *** ****** controllers **** ** *** SCP ****** *** *** impacted ** **** *****.

Over ****** ****** ****** ********

******* ******** ** ********* with * ***** ******* of *** ****** ******* market, **** ** ****** brands.

***** ******* ** ***** brands ******* ******** *** party ********** *******, ** any ** ****** *********** are **** **** ** a '*****' *********** ** multiple *****, *** ******** are ****** ** *** Mercury ***********.

*** ****** ***** ***** below ***** ****** ******* partners, ******** *** **** may *** ** *************:

Two ******* ** ******** ******

** ***** ** ****** the ****** ******** *******, every ******** ********** ***** to ** ********.

******* ******** ***** *** two ******* ** ************ the *** ******:

***** *** *** **** to ****** ***** ********:
  1. ****** **** **** *** PACS ********.
  2. ******* **** *** ***** webpage.

*******, *** *** ******** Mercury *********** *** ****** to ** ******** **********, and * *********** ****** of ******** ******* *** likely ** ** **** onsite, ********* ******* '**** trucks' ** ******** ********* to ****** *** ***.

Poll: ** **** ******** *******?

*********** *** ******** **** to ******* ******** *********, the ********** ******* *************, and *** ****** **** to ****** ********* **** is *** ******** **********, the **** ** *******'* 'Leap ****' ******* ***** be *********** *** **** dealers ** *******.

***********, ** *** **** to **** **** ********* a ******* **** ** do *** ****** ** do ** ****?

****:

Comments (80)

**** *******, *** ***** never ****.

**** ****** ** ********, but *** **** ******* I **** ******** ** fairly ******* *** ** and *** **** * customer ***** ****. *** other ******** * **** are ** ***** ** based ***********. * **** not ** *********. ****** in *** ******* *** much **** ******* *** I ******* **** **** have ** *******. **** our *******-***** ******* ****** firmware ******** ** ***** is ** ******. ** with * ****** ***** integrator, **** ***** ** great ******* **** **** we ****** * **** firmware *******.

******** *** **, ***'* do ****** ******** ** a ******. ******* **** came **** ****** ******** on * ******...

******** *** **, ***'* do ****** ******** ** a ******. ******* **** came **** ****** ******** on * ******...

******* **** ******, **** than ****, *******.

** ***** ** ***** time!

*** *** ** ** ten *********** ** *********. never ***** ** ********* job ** ******, ****** you **** ** **** that ******** *** ******** sunday

* *** **** *** we ** ******* **** have * ****** (**** we************* **) **** ** never ******* *** ******** or ******** ******* ** Fridays ******.

***'** *******.

***** *********** *****. ** this ***** ***** ****'* released **** *** **** yet *** ********* **** will ****.

******. * ****** ******* us, *** ********** ******* notifications *** ********* ***, like **** ******* **** RS2:

**** ** *** **** bigger ***** ** ** side ** *** *****. Where ** *** **** have ** ********* *** of *** *** * series ***********. ** **** locations ****** ** ******** firmware, ******, ******** ******** almost ***** ** *** of ******** ***** *** system ** ** **** downtime ** ********.

**** ***** **** ***'* a *** **** *** there *** **** **** this **** **. **** can ** **** ******** and ****** ***'*.

**** ** ***** ** take **** ********* ******** that ** *** *******. Good **** ** ** fellow *********** ** ************ this ****.

**** ** ***** ** take **** ********* ******** that ** *** *******.

**** ****** *** **** ;)

******* ******** ******** *******'* require * ******** ********. This *** ** *** software ********, *** ** is *** * *********. You ****** ******* **** the ******** ****** ** question.

** *** ***** ** you ***** **** **** may ****** ** **** you **** **** ** do. ** ****** **** dealing **** ***** *** prepare *** *** ***** and **** *** *** best.
* *** **** *** new * ****** *********** this ** ******** ** be ****** *** ** with ********** *** ***** know. *** ****** ******** is **** **** ******** break **** **** ******.

**** ************* **** **** pretty **** ***** *** notification ** **** ** possible **** ***** *****. Big ******** ****: ******* is ******* ***** ******** to ********* ********* **** asked. ** *** *** a ******* ******* ****** this ****** ** ****** and ******* ****** ********* proven ** *** *-****** boards.

* *** **** ** that ***. **’* ******* how ***** * ***’* signup *** ********* ***** my ****** ********!

**** *****: ***** ***** EOL ** ****.

***** ***** *******'* ****.

******* ****** ** ****:

******* ** **** ********* their *** ******** **** the *****. *** *** potential *** ***** *** getting **** ****** ******* numerous ********* **** **** significant ****** *** **** to ***** ****** ******* Sites . **, ** a ******** ******* ******** sold ********* *** ******** Mercury ******** *** ****'* current *** *******, *******'* position ** **** *** aren't ***** ** *** any *******. **'* * pretty **** ******** ** their **** *** *** protecting *** *** ***** with ******* ******** ******** issues.

*** *** * ******* partner *** *** ** longer **? * ****'* think **** *** **** an ****** *** * manufacturer. ** ***** **** once *** **** ****** boards ******** **'* ****** hard ** ******* ******** for *** **** ****** you *******.

*** ***** ******* ***** if ***-***** **** ********* of *** ******** *** now *** ***.

*** *******, ** **** stopped ****** *********** ***** and ******/********* ***** ** a ****** *** **** let *** ****** ******* in-situ ******* ****** *******.

*******, ** ***** ****** be * ***** ****** of ***** ***** *** new ** ****** ***, but ***** ******** ***** would **** ******* ********* with ** ***** ************ from ******* ** *** end-user.

**** ** **** **** his **** ******* ** series ***********, ***** **** been *** *** * relatively ***** ********. ***** doesn't ****** ** **** been *** ******** **** Merc **** ** **** time, ** **** *******'* really ** * *******.

**, * ***, **'* end-user ********. **** ***** fair ** **.

******* ********:

******* ** ********* ** all *** **** **** have **** *** ******** products ***** **** **** to *** ***** ** sales ** **** ****. All ** ***** ********* are ***** ******* ****.

** [ $$******* == '02-28-2020' ] ; ****

******* '**-**-****'

**

;)

** *****'* ***** **** current ***** ******* * very ******* ****** ** customers. ** ***** *** Mercury's ******** *** ** support ***** *** ******** with ******** ******* **** are ******** ** *** a **** ******** ******** nor ** ** ****** in *****'* ***********. ****** of ***** ******* *** Partners *** *** *** move **** **** ******* and ***** **** * larger ******** ** **** type ** ***** ** the ******.

** ******* ***** **** from *******, *** ***** a ******* ******** ******* even ****** **? ** they ***'* *** ******* then **** ***'* **** mercury ******** ** *** right?

**** *****, ***********, *** partners ******'* ** ***** LP ****** *********** ** non-legacy ****, ****** **** have **** ** ** their *** ******* ******* from ******* ** * don't *** *** *** think ******* ****** ************* support ****.

**** ******* *****'* **** any ***** *** * security ******* ** *** computer *******. ** * defect ** ********* ***** security **** ***** ** on * ******* **** was ******* & ********* in **** ***** *** now ***** *** *** user ****'* ********* **** or ****** ** *** of ***** ******** **** company *** ***'* *** responsible ** ***** ***** customers. **** ***'* * good ******** ********. *** would *** **** ** a ******* **** ** Microsoft *********** * ****** that ***** *** *****'* purchase ****** ******** **** them ** ***** ******** nor **** * ******* agreement, *** *** *** going ** *** *** system ******* ** ******** system *******? **** ********* follow * ******* ** provide ******** ******* *** patches *** ***** ******** and ******** ***** **** are *** ** ****.

***’* **** ***** ** endlessly ****? 🤣

***’* **** ***** ** endlessly ****?

Image result for groundhog day not bad for a quadruped

***’* **** ***** ** endlessly ****?

********* ;)

*'* ***** ******* * 30 *** *** ****** 2000 ***** ** * gateway ** **** **** success.

******* *** ****** **** pop-up ************ ** ***** portal:

******* ** ***** ** broadcasting *** *****, ******* says ***** '******* ****' are *** **** *********** for ******* **** ** end *****. ** * followup ** ****, ******* says:

  • *** ************ ******* *** first ******* *** *** partners. **** ****** ** do ***** ******* *** confirm *** ***.
  • *** **** *** **** the **** **** *** know ***** ****** *******. While ** ********* *** channel ** ** ********** on *** ******, **** is *** * ******** of *** ********.

**** ***** ** ******* '** *** ****** ** be ** ********* ** possible ** *** *** word ***.'

** **** **** **** a *** *** * cloud ******* ***** *** to ****** *****'* ******* here:

**'* ********* * **** point *** **** ****, at *****, ******** ** making *** **** *** more ***** ****** *******.

*** ***'* **** * cloud ** **** * centralized ****** ********. ** was ****** "******* ******", back ** *** ***...

*** **** ** ***** PACS ********* **** **** update **********? ** **** common?

*** ***'* **** * cloud ** **** * centralized ****** ********. ** was ****** "******* ******", back ** *** ***...

"******* ******" ****** **** from *** *****.

** **** ****'* **** the ****, **** ** the ***.

******* ****** *** **** onsite ****** **** **** outside **** ****, ***. that's *** *** **** as * ***** ********.

**** **'* * *** disturbing **** *** ******* are ******* ** ** different ***** **** ********* vendors. **** **** ******** the ***** ******* ****'* exist ***** **** ***** so **** *** ****** pushing...

**** **** ******** *** legit ******* ****'* ***** until **** ***** ** what *** ****** *******...

*** **** ******* ******** to ***** *** ******** mid-January. ********** ******** ******* the ********** '****** *** verified' ******** ** ******* on ***** *** ******** schedule.

**** ** ***** ******* has ***-******** ****** *** released *** ***. ***** me * ***** ****!

* ******** **** *** handling * ****** ******** genetec ****** ******* *** was ******** ** * monthly ***** ** ***** all ** ***** ******* update **** ******** *** software. **** ******* **** way ****** *** ******* and ********* *** ******* contract **** ***** ****** unofficially ** ****'* **** effective *** **** ****'* see * **********.

**** **** ** **** an ***** *** ** these ****** ********* ********** the ***** ** ***** buildings...... ** **** * am **** ** **** be **** ** ** change ****** *** *** contracts ****** *******

*** ****** ********* **** on *** ***** ***? If **, **** ** what *******.

********'* **** ****, *****? If ******* **** *** might **** ** **** the **** ** **** solution ** ******* **** is *** **** ****-***** .. ********* **** ********** ask...

**’* **** * *** years ***** * ****** on ***** *******, *** back **** *** ***** load * ******** ****** into *** ******* *** schedule **** ** ***** push **.

***** **** **** ***’* as *** ** ***** for ****, ****** *’* wrong.

*** **** ******* **** come ** ***** ********* that *** ******* *********** versions (*** *.*) ** the ******** ****'* **** tested *****. *** **** from *.* ** *.* takes **** ****** ************ on **** ** *** enterprise *********, ********** **** large *****-****** ***********.

*** ****** **** ******* the ******** **** *******? older ******** ** ***** (7.4 *** *****) ******* in ****** **** ** are *** ********. ***** versions ** ******* (*.* and *****) ******* ** Legacy **** ** *** NOT ********. **** ***** that *** **** *** customers *** ***'* ****** to **** ** **** their ****/**** *******/*** ** whatever *** ****** ****** to ** ** ** NOT **** **** *******! unless *** **** * customer **** *** ***** service ********* ****** **** recently *** *** **** up ** ****, **** is *** ** ***** at ***.

** *** *** ******** of '**** ** *** customer ***** ** * different ******** ** *** future' **** ** **** ridiculous ** **** *** here ** *******'* *******. regardless ** **** ******/******** it **, *** **** have ** ******** **** sort ** ******** **** you ****** ****, ** this ***** ** **** nonsense.

******. **** **** *** if **** ** ******* upgrade ** * *** version **** *** **** be ******* ******** ********* at *** **** ****** and *** ******** **** also ** ******** *** this.

***, ***** *** *** the ******! ***** *** those ** ** **** different ********* ****, ********* different ************* ** ****.

** ************* **** *** Synergis ******* **** *****'* include *** ***** ** legacy ****. ************, *******'* posted ***-***** *** ** mention ** ****** ****.

**** * ******** ***********, that's *** *** *********** they ****.

*****, **** ** ******* Stamatelos, ******* ********* *******, access ******* ** *******.

* ***** **** ** clarify *** ******* ***** stating **** ***** ******** Center ******** (*.* *** prior) ******** ** ****** mode *** *** *** affected ** **** *****.This ********* ** **********.

****** ** *** ********** feature ********* ******* *** Synergis ***** **** *****-****** architecture, *** ** ****** have **** ********* ********** with ***** ******** ** Security ****** ** ******** compatibility ****. ********* ** panels ****** ** ** panels ** ***** ********, prior ** *.* (******** in *** ****). ** such, ******* *** ***** used *** ****** **** to ********* *** ******* LP ****** ** ******** Center.

** ******* ****ALL ** ****** are affected by this issue and Genetec customers must upgrade to Mercury firmware 1.29.0 regardless of the Security Center version being used. “

**** *******,

*******

*** *** *** ** bulk *******.

*** ** ******* **** firmware ****** *** ** also ****** *** ** on *** ** ** in *** ************.

**** ** *** **** as ** **** *** been *******. ** *****’* matter **** ****** ** is, *** *** ***** push * **** ******** and ** ****** ***** out *****.

*** **** ***** ** when *** ***** *** the "*** **** * staging ******, *****?" *********. Let ** *****, ***'** a ****** **********, *** have **** ******* *** they're *** ***** *** nobody *** ****** *** a **** ******...

* ***** ** *** end ** ****** ** happy **** ******* **** out ****** *** **** has *******!!

******* *** **** * tech ******** ** ******* on **** *****:

******* ******** ******** ***** "can" ** **** ****** but **'* *** ********* more **** (*?) ** a ****. ** ***** be *********** ** **** some ******** **** ***** users *** **** ****** the ******...

**** ****** ** * full **** *** * half ****** *** ***** Mercury-based *************. *** ****** is **** ***** * week *** * **** after *** ***** ******** we ******** **** ** queried ******* ** *** same ****. ****'* ****... but ** ***** ** is *** ****-********!

** **** *** ******* partner **** *** **** told ** *** **** affected ****** ***** *** but **** ****** *** of *** *** ** purchased **** ** ** we **** **** ********* the ***** ********. *** unprovoked. ** **, **** was **********.

***** *** **** ******* the ************ **** *** that? ***** **'* ********** and ****-******** *********.

** ** *****, *'* not ****** * ******* question ****...*'* *** * manufacturer, *** * **** no **** *** *** that...but ** ************ ******* to *****.

****** **** ** *********'* Pro-Watch ****** *** ********? I ******* **** ***** up **** ** ********, but **** ***'* **** concerned. ********* ** *********** slow **** ******* *** information.

********* ******* ** ** consider *** *****-**** ********..........** my **********......

(******* ***** ****...) ********* uses ***** *** ******** (EP1501 *****?) ******* *******'* software. * ***** ***** they *** *** ***** Linux (*.*. *** ******** in *** ** ******.)

********* ****** *** *** effected. *******, ********* **** sells *** ******** ********* Mercury, ** **'* ******** customers ***** **** **.

* ******* *** ******** supplied ******** ****** ** our ****** ******. ** short, *** ****** ****** problems *** *** ************; the ****** ******* ******* properly. * ****** *** firmware **** *** ** returned ** ******. ******** performed **** ******* ********, but **** ****** ** explain *** ********. * recommend ******* *** ******* closely.

*******:

******!** **** ***** ******** for *******/******* ** ****.

****** *** *** *****, Brian. ******** *** **** in ***** **** ** and ** ******** *********** the ******.

***** **** *******, ******** identified *** *****. * have **** *********** **** no ******* ******** (*** example, ******* **** *****). The ******* ***** **** the ******* ******** *** not ******* ******** ***** Avigilon ***** ** * software "***** ******". ******** forwarded *** *********** ** Mercury, *** ** ** yet ***** *** *** been *** ********** **** will ******* ******* ********. At ***** * **** the ****-******.

****** *******. ** **** reached *** ** ******* for ******* ** ****.

[******] ***** *** *********** listed ** ** ******** partner. **** *** *** a ******* ******* *** have **** *******.

******.

* **** ******* * x ****** *********** **** in ** ** ************.
*** *** ******* **: 1.27.8 (***)
*** ************ **** ******* any ******.
***** *'** **** ** it's ***** ** ***** 1st.
**** ***** * *** was ********** ******* * DIP ****** ** **** board ** * ***** login **** *** ******* credentials. * **** ***** and ******* * **** on **** ** **** to **** ****** ******* simpler.

** ** ** ************* they *** ******** ******** to ** ** *.**. You ******** **** ** verify ***'** ******** ** be ** * (*** older) *******.

* **** ***** ** supplier ** ****** *** version ** **** ** is *******.

*’* ******** **** * created * **** ** each ** *** ******... just ** ****!

** ********** ** ***** saying **** ** ********** being ** *.**.*
** ****** **** ** knows *********, *'* ********** the ********.

* **** *** ******* and ****** **** ****.

**** ** **'* ********:

** **** *.**.*. ****, we ********* **** **** panels ** ****** ****, which ***** ***** *** issue **********, *** ** installer ***** ****** ****.

****** *** *** ********** know **** *** ******* team ** ********* ** answer ***** ********* ****** this **** ** ****** come **.

***** * **** **** for **** ********* ****:

**** ** *********** *** I ** ***** ** leave ** **** *** statement **** ** ** poor ***** ** ***** your **********.

** ** ***** ** customers / ********, * can *** *** ** makes ***** ****** ****** the ********* ***** ** some ****** ***** ********* be ********* ***** *** is ********.

*'** ******* ***** ** gloat **** **** *********** slip, *** ***** ** the **** ***...********** ** this ********.

******. **** ***** ***** was ** ******** *****. Just ********* *** ******** that ** ******* **** Year, *** ****** **** :)

*** ***** * ********** makes * ******* *** this ******* ***'* ****** until *** ****** ** running *** ** *** wild. ******** ***** ******** it ** *** *** handle *** ******* ***** separates *** ***********. * was ***** ** *** over * ****** ****** about **** *****.

*************, **** (******** *****) is **** ****** ******* statements *** *******:

******* *** ***** ******** updates *** ***** *** folks. ****** ********* *********** issues **** *** ******** upgrade *******? ****** ******** and *** ********* ***..? What ** *** ******* down **** ** * panel ****** **** *******?

*'** **** ******** ** two ******** ******* (******** and *******) *** *** no ****** **** ****** one. **** ** ******** depends ** * ******* of *******, *** ****** more **** **** * couple ** *******. *** only *** **** **** longer *** * ***** in *********, *** ********** takes ****** ** *** there ** *** **** surprising.

* **** **** ***** firmware ******* ****** *********, so * ****'* ****** from ******** ********* ** get *****.

** *** **** ***** boards ***** *** *** took * *** ******* and ******, ***** **** across *** ******* **** almost ** ****.

Read this IPVM report for free.

This article is part of IPVM's 6,735 reports, 909 tests and is only available to members. To get a one-time preview of our work, enter your work email to access the full article.

Already a member? Login here | Join now
Loading Related Reports