CVE-2020-7215
Published Jan 20, 2020
Last updated 3 years ago
Overview
- Description
- An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-532
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F5D71D9-ECE3-49AB-BE6E-62390C018B6F", "versionEndExcluding": "7.80" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6093704-EB1F-4B41-A9BA-EAF5EBBE86E1", "versionEndExcluding": "7.90.991", "versionStartIncluding": "7.90" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C8C50BE-CE33-47F5-87D7-72EC8A069C03", "versionEndExcluding": "8.00.1161", "versionStartIncluding": "8.00" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F25C56A-EFE0-407A-B682-E25C5665CAB5", "versionEndExcluding": "8.10.1134", "versionStartIncluding": "8.10" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:7.90.991:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B374C701-59BA-4BDC-A2CD-5EE40A253746" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:8.00.1161:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BE2F182-7215-4A41-86F5-B8F6F307E779" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:8.10.1134:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0676CE27-3D08-4619-89A6-7A17B37B3665" } ], "operator": "OR" } ] } ]