5.6
CVE-2026-20801
- EPSS 0.1%
- Veröffentlicht 03.03.2026 03:15:54
- Zuletzt bearbeitet 17.08.2026 19:03:02
- CVE-Watchlists
- Unerledigt
Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gallagher ≫ Hanwha Vms Integration SwPlatformcommand_centre Version < 9.10.025
Gallagher ≫ Nx Witness Vms Integration SwPlatformcommand_centre Version < 9.10.017
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.011 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosures@gallagher.com | 5.6 | 2.2 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20801