CVE-2021-23182
11.06.2021, 16:15
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); All versions of 8.30.Enginsight
Vendor | Product | Version |
---|---|---|
gallagher | command_centre | 8.30 ≤ 𝑥 < 8.40.1888 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-316 - Cleartext Storage of Sensitive Information in MemoryThe application stores sensitive information in cleartext in memory.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.