CVE-2020-16101

It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:8.00.1228:-:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:8.10.1211:-:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:8.20.1166:-:*:*:*:*:*:*

History

21 Nov 2024, 05:06

Type Values Removed Values Added
References () https://security.gallagher.com/Security-Advisories/CVE-2020-16101 - Vendor Advisory () https://security.gallagher.com/Security-Advisories/CVE-2020-16101 - Vendor Advisory

Information

Published : 2020-09-15 14:15

Updated : 2024-11-21 05:06


NVD link : CVE-2020-16101

Mitre link : CVE-2020-16101

CVE.ORG link : CVE-2020-16101


JSON object : View

Products Affected

gallagher

  • command_centre
CWE
CWE-805

Buffer Access with Incorrect Length Value

CWE-125

Out-of-bounds Read