Data Exposure in Gallagher Command Centre Affecting Multiple Versions
CVE-2020-16096

9.9CRITICAL

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
15 September 2020

What is CVE-2020-16096?

In Gallagher Command Centre, various versions are vulnerable to a data exposure issue that permits any operator account to access sensitive data. This data includes plain text credentials for DVR systems and sensitive card details relative to physical access, alarm systems, and perimeter security. If these vulnerabilities exist, any account within the affected versions can potentially exploit them, particularly if the system is configured to integrate within a multi-server environment.

Affected Version(s)

Command Centre <= 7.70

Command Centre 8.10 < 8.10.1134(MR4)

Command Centre 8.00 < 8.00.1161(MR5)

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.