← Back to CVEs
CVE-2020-16100
HIGH7.5
Description
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configuration Client) connections. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.
CVE Details
CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published9/15/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
gallagher:command_centre
Weaknesses (CWE)
CWE-404CWE-404
References
https://security.gallagher.com/Security-Advisories/CVE-2020-16100(disclosures@gallagher.com)
https://security.gallagher.com/Security-Advisories/CVE-2020-16100(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.