Gallagher HBUS Devices Observable Timing Discrepancy Vulnerability Allowing Key Extraction

Vulnerability

A timing discrepancy vulnerability has been identified in HBUS devices, which may allow an attacker with physical access to the device to extract device-specific keys. This could potentially compromise further site security. The vulnerability arises from an observable timing discrepancy, categorized under CWE-208.

Impact

Exploitation of this vulnerability could lead to the unauthorized extraction of device-specific keys, potentially compromising the security of the site.

Remediation

Users are advised to ensure that hardware is installed correctly and to follow all steps from the hardening guide.

Added: Nov 18, 2025, 4:17 AM
Updated: Nov 18, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
3.5
remediation
7.9
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.