Discover the impact of CVE-2020-7215 in Gallagher Command Centre versions 7.x, 8.00, and 8.10. Learn about the exposure of sensitive configuration data and how to mitigate this security risk.
Gallagher Command Centre versions 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4) are affected by a vulnerability that exposes external system configuration data, including sensitive information like usernames and passwords, to authenticated operators with specific privileges.
Understanding CVE-2020-7215
What is CVE-2020-7215?
The vulnerability in Gallagher Command Centre versions allows authenticated operators to view cleartext usernames and passwords in the event details of a Modified DVR System event.
The Impact of CVE-2020-7215
The exposure of sensitive configuration data poses a significant security risk, potentially leading to unauthorized access to integrated third-party systems.
Technical Details of CVE-2020-7215
Vulnerability Description
The issue stems from the logging of external system configuration data in the Command Centre event trail, accessible to operators with 'view events' privilege.
Affected Systems and Versions
Exploitation Mechanism
Operators with the 'view events' privilege can exploit this vulnerability to access sensitive configuration data, compromising system security.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Apply security patches provided by Gallagher Security to address the vulnerability and enhance system security.