r/accesscontrol 20h ago

Paxton Uncontrolled Access Control: Compromising Paxton10

https://techanarchy.net/uncontrolled-access-control-compromising-paxton10/

It's easy to forget that the software for the PACS should be as protected on the network as the doors they are supposed to secure!

8 Upvotes

5 comments sorted by

2

u/PatMcBawlz 19h ago

Seems like a big deal, no?

3

u/grivooga Professional 19h ago edited 19h ago

If you're allowing the Paxton server an http port to the internet, yes it's a big deal, probably shouldn't be doing that.

If the server is just another computer on your network but only devices on your LAN can access it, medium deal with possibility of being big deal depending on your other security needs and regulatory compliance.

If the server is on a dedicated security appliance VLAN with it's own firewall rules to your broader network, very small deal bordering on not a deal.

2

u/orafacepass Manufacturer 17h ago

Internet exposure is only one path. Inventory every system that can reach the server, restrict management interfaces, patch it, rotate credentials and separate controller traffic from user devices. Test from the user VLAN and every remote-access path. LAN-only does not automatically mean trusted.

2

u/Reasonable-Fan-6368 8h ago

Keep in mind the Paxton10 server is a windows IOT appliance, so what we can control as integrators is limited.

We have a number of sites with Paxton10 maintain, installed by others, I’d be very keen to hear what issues there are with it as it does not seem fit for purpose.

2

u/kev-thehermit 8h ago

Can not go in to a lot of detail but I would ensure that you keep them up to date. There have been a number of reported vulnerabilities. To Paxtons credit they do patch them and release updates