6.5

CVE-2019-19802

In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OPCUA can view all data that would be replicated in a multi-server setup without privilege checks being applied.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GallagherCommand Centre Version < 7.70
GallagherCommand Centre Version >= 7.80 < 7.80.960
GallagherCommand Centre Version >= 7.90 < 7.90.991
GallagherCommand Centre Version >= 8.00 < 8.00.1161
GallagherCommand Centre Version >= 8.10 < 8.10.1134
GallagherCommand Centre Version7.80.960 Update-
GallagherCommand Centre Version7.90.991 Update-
GallagherCommand Centre Version8.00.1161 Update-
GallagherCommand Centre Version8.10.1134 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.411
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.