CVE-2020-7215
https://notcve.org/view.php?id=CVE-2020-7215
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event. Se detectó un problema en Gallagher Command Center versiones 7.x anteriores a 7.90.991(MR5), versiones 8.00 anteriores a 8.00.1161(MR5) y versiones 8.10 anteriores a 8.10.1134(MR4). Los datos de configuración del sistema externo (utilizados para integraciones de terceros, tales como los sistemas DVR) fueron registrados en el registro de eventos de Command Centre. • https://security.gallagher.com/cve-2020-7215 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2019-19802
https://notcve.org/view.php?id=CVE-2019-19802
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OPCUA can view all data that would be replicated in a multi-server setup without privilege checks being applied. En Gallagher Command Center Server versiones v8.10 anteriores a v8.10.1134(MR4), versiones v8.00 anteriores a v8.00.1161(MR5), versiones v7.90 anteriores a v7.90.991(MR5), versiones v7.80 anteriores a v7.80.960(MR2) y versión v7.70 o anteriores, un usuario autenticado que conecta con OPCUA puede visualizar todos los datos que se replicarían en una configuración multiservidor sin ser aplicadas comprobaciones de privilegios. • https://security.gallagher.com/cve-2019-19802 • CWE-862: Missing Authorization •
CVE-2019-19801
https://notcve.org/view.php?id=CVE-2019-19801
In Gallagher Command Centre Server versions of v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an unprivileged but authenticated user is able to perform a backup of the Command Centre databases. En Gallagher Command Center Server versiones v8.10 anteriores a v8.10.1134(MR4), versiones v8.00 anteriores a v8.00.1161(MR5), versiones v7.90 anteriores a v7.90.991(MR5), versiones v7.80 anteriores a v7.80.960(MR2) y versión v7.70 o anteriores, un usuario no privilegiado pero autenticado es capaz de realizar una copia de seguridad de las bases de datos de Command Center. • https://security.gallagher.com/cve-2019-19801 •
CVE-2019-15294
https://notcve.org/view.php?id=CVE-2019-15294
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file. Se descubrió un problema en Gallagher Command Center versiones 8.10 anteriores a 8.10.1092 (MR2). Luego de una actualización, si una cuenta de servicio personalizado está en uso y el servicio de administración de visitantes está instalado, el nombre de usuario y la contraseña de Windows para este servicio son registrados en texto sin cifrar en el archivo Command_centre.log. • https://security.gallagher.com/CVE-2019-15294 https://security.gallagher.com/security-advisories • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2019-12492
https://notcve.org/view.php?id=CVE-2019-12492
Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services. Gallagher Command Center anterior de 7.80.939, 7.90.x anterior de 7.90.961, y 8.x anterior de las 8.00.1128 permite la creación de eventos arbitrarios y la revelación de información a través de los servicios FT Command Center Service y FT Controller Service. • https://security.gallagher.com/CVE-2019-12492 https://security.gallagher.com/security-advisories • CWE-863: Incorrect Authorization •