Sensitive Information Exposure in Gallagher Controller 6000
CVE-2023-41967

2.4LOW

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
18 December 2023

What is CVE-2023-41967?

The Gallagher Controller 6000 is susceptible to a vulnerability that allows an attacker with physical access and knowledge of the default diagnostic password to view sensitive configuration details through its diagnostic web pages. This issue arises after a debug/power state transition, where sensitive information remains uncleared, potentially allowing unauthorized users to exploit this weakness.

Affected Version(s)

Controller 6000 0 <= 8.60

Controller 6000 8.70

References

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.