// For flags

CVE-2020-16097

 

Severity Score

4.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.

En controladores que ejecutan versiones desde v8.20 anteriores a vCR8.20.200221b (distribuido en versión v8.20.1093(MR2)), versiones v8.10 anteriores a vGR8.10.179 (distribuido en versión v8.10.1211(MR5)), versiones v8.00 anteriores a vGR8 .00.165 (distribuido en versión v8.00.1228(MR6)), versiones v7.90 anteriores a vGR7.90.165 (distribuido en v7.90.1038(MRX)), versiones v7.80 o anteriores, es posible recuperar las claves del sitio usadas para proteger MIFARE Plus y Desfire por medio de puertos de depuración en lectores de la Serie T

*Credits: Matthew Daley of Aura Information Security
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-07-28 CVE Reserved
  • 2020-09-15 CVE Published
  • 2023-06-01 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-522: Insufficiently Protected Credentials
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 7.90 < 7.90.1038
Search vendor "Gallagher" for product "Command Centre" and version " >= 7.90 < 7.90.1038"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 8.00 < 8.00.1228
Search vendor "Gallagher" for product "Command Centre" and version " >= 8.00 < 8.00.1228"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 8.10 < 8.10.1211
Search vendor "Gallagher" for product "Command Centre" and version " >= 8.10 < 8.10.1211"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 8.20 < 8.20.1093
Search vendor "Gallagher" for product "Command Centre" and version " >= 8.20 < 8.20.1093"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
7.90.1038
Search vendor "Gallagher" for product "Command Centre" and version "7.90.1038"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
8.00.1228
Search vendor "Gallagher" for product "Command Centre" and version "8.00.1228"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
8.10.1211
Search vendor "Gallagher" for product "Command Centre" and version "8.10.1211"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
8.20.1093
Search vendor "Gallagher" for product "Command Centre" and version "8.20.1093"
-
Affected