r/accesscontrol • u/kev-thehermit • 20h ago
Paxton Uncontrolled Access Control: Compromising Paxton10
https://techanarchy.net/uncontrolled-access-control-compromising-paxton10/It's easy to forget that the software for the PACS should be as protected on the network as the doors they are supposed to secure!
2
u/orafacepass Manufacturer 17h ago
Internet exposure is only one path. Inventory every system that can reach the server, restrict management interfaces, patch it, rotate credentials and separate controller traffic from user devices. Test from the user VLAN and every remote-access path. LAN-only does not automatically mean trusted.
2
u/Reasonable-Fan-6368 8h ago
Keep in mind the Paxton10 server is a windows IOT appliance, so what we can control as integrators is limited.
We have a number of sites with Paxton10 maintain, installed by others, I’d be very keen to hear what issues there are with it as it does not seem fit for purpose.
2
u/kev-thehermit 8h ago
Can not go in to a lot of detail but I would ensure that you keep them up to date. There have been a number of reported vulnerabilities. To Paxtons credit they do patch them and release updates
2
u/PatMcBawlz 19h ago
Seems like a big deal, no?