← Back to browse · API

CVE-2020-16096

Severity
CRITICAL
CVSS
9.9
EPSS
0.008
Risk score
39.88
CISA KEV
No
PoC
No
Published
2020-09-15
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-8062, GHSA-95HF-GV4R-6JJR
Products
Gallagher:Command Centre 7.80 <7.80.960(MR2), Gallagher:Command Centre 7.90 <7.90.991(MR5), Gallagher:Command Centre 8.00 <8.00.1161(MR5), Gallagher:Command Centre 8.10 <8.10.1134(MR4), Gallagher:Command Centre unspecified ≤7.70
Sources
euvd EUVD-2020-8062

Description

In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system were to be (or is) attached to a multi-server environment. This can include plain text credentials for DVR systems and card details used for physical access/alarm/perimeter components.

References