6.5

CVE-2019-12492

Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GallagherCommand Centre Version < 7.80.939
GallagherCommand Centre Version >= 7.90.0 < 7.90.961
GallagherCommand Centre Version >= 8.0 < 8.00.1128
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.74% 0.497
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.2 4.2
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://security.gallagher.com/CVE-2019-12492
Vendor Advisory
Mitigation
https://security.gallagher.com/security-advisories
Vendor Advisory