// For flags

CVE-2020-7215

 

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event.

Se detectó un problema en Gallagher Command Center versiones 7.x anteriores a 7.90.991(MR5), versiones 8.00 anteriores a 8.00.1161(MR5) y versiones 8.10 anteriores a 8.10.1134(MR4). Los datos de configuración del sistema externo (utilizados para integraciones de terceros, tales como los sistemas DVR) fueron registrados en el registro de eventos de Command Centre. Cualquier operador autenticado con el privilegio "view events" podría visualizar la configuración completa, incluyendo los nombres de usuario y contraseñas en texto sin cifrar, bajo los detalles de evento de un evento Modified DVR System.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-16 CVE Reserved
  • 2020-01-20 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
< 7.80
Search vendor "Gallagher" for product "Command Centre" and version " < 7.80"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 7.90 < 7.90.991
Search vendor "Gallagher" for product "Command Centre" and version " >= 7.90 < 7.90.991"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 8.00 < 8.00.1161
Search vendor "Gallagher" for product "Command Centre" and version " >= 8.00 < 8.00.1161"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
>= 8.10 < 8.10.1134
Search vendor "Gallagher" for product "Command Centre" and version " >= 8.10 < 8.10.1134"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
7.90.991
Search vendor "Gallagher" for product "Command Centre" and version "7.90.991"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
8.00.1161
Search vendor "Gallagher" for product "Command Centre" and version "8.00.1161"
-
Affected
Gallagher
Search vendor "Gallagher"
Command Centre
Search vendor "Gallagher" for product "Command Centre"
8.10.1134
Search vendor "Gallagher" for product "Command Centre" and version "8.10.1134"
-
Affected