CVE-2020-16102

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1299(MR2); 8.20 versions prior to 8.20.1218(MR4); 8.10 versions prior to 8.10.1253(MR6); 8.00 versions prior to 8.00.1252(MR7); version 7.90 and prior versions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
GallagherCNA
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
gallaghercommand_centre
𝑥
< 7.90.0
gallaghercommand_centre
8.00 ≤
𝑥
< 8.00.1252
gallaghercommand_centre
8.10 ≤
𝑥
< 8.10.1253
gallaghercommand_centre
8.20 ≤
𝑥
< 8.20.1218
gallaghercommand_centre
8.30 ≤
𝑥
< 8.30.1299
gallaghercommand_centre
8.00.1252
gallaghercommand_centre
8.00.1252:maintenance_release7
gallaghercommand_centre
8.10.1253
gallaghercommand_centre
8.10.1253:maintenance_release6
gallaghercommand_centre
8.20.1218
gallaghercommand_centre
8.20.1218:maintenance_release4
gallaghercommand_centre
8.30.1299
gallaghercommand_centre
8.30.1299:maintenance_release2
𝑥
= Vulnerable software versions