Talk

Swiss PACS: Two Tales of Vulnerability Disclosure

Swiss PACS: Two Tales of Vulnerability Disclosure

conf 2026-11-05 14:10 – 14:40 EN

Swiss PACS: Two Tales of Vulnerability Disclosure

Most Physical Access Control Systems (PACS) research focuses on badges, backend systems, or components that are only exposed after an attacker already has network access or is in possession of a badge. That means the much of the existing research often overlooks the core component exposed at the perimeter – the badge reader.

Our work looks at the badge reader at the edge of the perimeter, physically exposed by design and deployed in real Swiss environments, including critical ones. We analyzed proprietary protocols used by two leading Swiss badge reader vendors and found new vulnerabilities in their proprietary protocols that allow attackers to manipulate readers and gain unauthorized access. Even if the systems use state of the art badge-technology such as Legic Advant, since the attacks directly target the reader.

We highlight two very different disclosure journeys with Swiss vendors - one requiring escalation via National Testing Center (NTC) and BACS, the other highly collaborative – sharing our lessons learned.

This talk combines technical research with practical disclosure experience. It is a case study in how insecure perimeter PACS components can be abused, how such systems can be tested, and how researchers, vendors, customers, and Swiss institutions can work together more effectively.