CVE-2020-16097

EUVD-2020-8063
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
GallagherCNA
7.3 HIGH
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
gallaghercommand_centre
7.90 ≤
𝑥
< 7.90.1038
gallaghercommand_centre
8.00 ≤
𝑥
< 8.00.1228
gallaghercommand_centre
8.10 ≤
𝑥
< 8.10.1211
gallaghercommand_centre
8.20 ≤
𝑥
< 8.20.1093
gallaghercommand_centre
7.90.1038
gallaghercommand_centre
8.00.1228
gallaghercommand_centre
8.10.1211
gallaghercommand_centre
8.20.1093
𝑥
= Vulnerable software versions