CRITICAL🇵🇱 Wersja polska

CVE-2020-16096

CVSS 9.9v3.1pub. 2020-09-15upd. 2024-11-21

In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system were to be (or is) attached to a multi-server environment. This can include plain text credentials for DVR systems and card details used for physical access/alarm/perimeter components.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Gallagher Command Centre

    APP
    Gallagher
    7.80.9607.90.9918.00.11618.10.11348.10 – 8.10.1134 (excl.)8.00 – 8.00.1161 (excl.)7.90 – 7.90.991 (excl.)7.80 – 7.80.960 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21815CRITICAL9.1PL ✓same product

Gallagher Command Centre: niechronione dane uwierzytelniające integracji DVR

CVE-2021-23230CRITICAL9.9PL ✓same product

SQL Injection w interfejsie OPCUA Gallagher Command Centre

CVE-2021-23140CRITICAL9.9PL ✓same product

Nieprawidłowa autoryzacja w Gallagher Command Centre — modyfikacja makr

CVE-2020-16098CRITICAL9.8PL ✓same product

Gallagher Command Centre — nieuprawnione odczytanie danych kart dostępu

CVE-2019-15294CRITICAL9.8PL ✓same product

Gallagher Command Centre: hasło logowane jawnym tekstem w pliku logu