CVE-2020-7215 Information
Feb 14, 2021
cve
Description
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5) 8.00 before 8.00.1161(MR5) and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the ‘view events’ privilege could see the full configuration including cleartext usernames and passwords under the event details of a Modified DVR System event.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://security.gallagher.com/cve-2020-7215
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.5
Share on: