Cleartext Storage Vulnerability in Gallagher Command Centre Server
CVE-2021-23182

6MEDIUM

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
11 June 2021

What is CVE-2021-23182?

A vulnerability in Gallagher Command Centre Server enables the storage of sensitive information in memory in cleartext, allowing for potential exposure of OSDP reader master keys within server memory dumps. This affects Gallagher Command Centre versions 8.40 prior to 8.40.1888 (MR3) and all versions of 8.30, posing a risk to data confidentiality and integrity.

Affected Version(s)

Command Centre 8.30

Command Centre 8.40 < 8.40.1888 (MR3)

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.