CVE Vulnerabilities

CVE-2020-16103

Incorrect Type Conversion or Cast

Published: Dec 14, 2020 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); version 8.00 and prior versions.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

Name Vendor Start Version End Version
Command_centre Gallagher * 8.00 (including)
Command_centre Gallagher 8.10 (including) 8.10.1211 (excluding)
Command_centre Gallagher 8.20 (including) 8.20.1166 (excluding)
Command_centre Gallagher 8.30 (including) 8.30.1236 (excluding)
Command_centre Gallagher 8.10.1211 (including) 8.10.1211 (including)
Command_centre Gallagher 8.10.1211-maintenance_release5 (including) 8.10.1211-maintenance_release5 (including)
Command_centre Gallagher 8.20.1166 (including) 8.20.1166 (including)
Command_centre Gallagher 8.20.1166-maintenance_release3 (including) 8.20.1166-maintenance_release3 (including)
Command_centre Gallagher 8.30.1236 (including) 8.30.1236 (including)
Command_centre Gallagher 8.30.1236-maintenance_release1 (including) 8.30.1236-maintenance_release1 (including)

References