Sensitive Information Exposure in Gallagher Controller 6000
CVE-2023-41967
2.4LOW
What is CVE-2023-41967?
The Gallagher Controller 6000 is susceptible to a vulnerability that allows an attacker with physical access and knowledge of the default diagnostic password to view sensitive configuration details through its diagnostic web pages. This issue arises after a debug/power state transition, where sensitive information remains uncleared, potentially allowing unauthorized users to exploit this weakness.
Affected Version(s)
Controller 6000 0 <= 8.60
Controller 6000 8.70
References
CVSS V3.1
Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
