CVE-2020-16102
- EPSS 1.03%
- Veröffentlicht 14.12.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:46
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects: Gallagher ...
CVE-2020-16103
- EPSS 2.2%
- Veröffentlicht 14.12.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:47
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.11...
CVE-2020-16104
- EPSS 0.9%
- Veröffentlicht 14.12.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:47
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary SQL against a third party database if EDI is configured to import data...
CVE-2020-16101
- EPSS 1.04%
- Veröffentlicht 15.09.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:46
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8....
CVE-2020-16100
- EPSS 1.04%
- Veröffentlicht 15.09.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:46
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configura...
CVE-2020-16099
- EPSS 0.8%
- Veröffentlicht 15.09.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:46
In Gallagher Command Centre v8.20 prior to v8.20.1093(MR2) it is possible to create Guard Tour events that when accessed via things like reporting cause clients to temporarily hang or disconnect.
CVE-2020-16098
- EPSS 1.09%
- Veröffentlicht 15.09.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:46
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), versions of 8.00 prior to v8.00.1228(...
CVE-2020-16097
- EPSS 0.31%
- Veröffentlicht 15.09.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:46
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (...
CVE-2020-16096
- EPSS 0.8%
- Veröffentlicht 15.09.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:46
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the s...
CVE-2020-7215
- EPSS 0.3%
- Veröffentlicht 20.01.2020 06:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:50
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Co...