SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-16102

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart.

HIGH 8.2EPSS 1.04%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1299(MR2); 8.20 versions prior to 8.20.1218(MR4); 8.10 versions prior to 8.10.1253(MR6); 8.00 versions prior to 8.00.1252(MR7); version 7.90 and prior versions.

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS
1.04% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-287, CWE-306
Affected
gallagher/command centre
Source
disclosures@gallagher.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.