CVE Vulnerabilities

CVE-2020-16096

Published: Sep 15, 2020 | Modified: Sep 24, 2020
CVSS 3.x
7.7
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system were to be (or is) attached to a multi-server environment. This can include plain text credentials for DVR systems and card details used for physical access/alarm/perimeter components.

Affected Software

Name Vendor Start Version End Version
Command_centre Gallagher 7.80 *
Command_centre Gallagher 7.80.960 7.80.960
Command_centre Gallagher 7.90 *
Command_centre Gallagher 7.90.991 7.90.991
Command_centre Gallagher 8.00 *
Command_centre Gallagher 8.00.1161 8.00.1161
Command_centre Gallagher 8.10 *
Command_centre Gallagher 8.10.1134 8.10.1134

References