Back to overview

CVE-2020-16096

CRITICAL
9.9
CVSS 3.1
Description
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system were to be (or is) attached to a multi-server environment. This can include plain text credentials for DVR systems and card details used for physical access/alarm/perimeter components.

Metadata

CVE ID
CVE-2020-16096
State
PUBLISHED
Assigner
Gallagher
Reserved
2020-07-28 00:00 UTC
Published
2020-09-15 13:24 UTC
Last updated
2024-08-04 13:37 UTC
Primary CWE
CWE-285
CWE-285 Improper Authorization
Vendor / Product
Gallagher / Command Centre
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Gallagher Command Centre unspecified ≤ 7.70, 8.10 < 8.10.1134(MR4), 8.00 < 8.00.1161(MR5), 7.90 < 7.90.991(MR5) …
Weakness (CWE)
CWESourceDescription
CWE-285 cna CWE-285 Improper Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview