CVE-2020-16097 (GCVE-0-2020-16097)
Vulnerability from cvelistv5
Published
2020-09-15 13:19
Modified
2024-08-04 13:37
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-522 - Insufficiently Protected Credentials
Summary
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.
References
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
Gallagher | Command Centre |
Version: unspecified < Version: vCR8.20 < vCR8.20.200221b Version: 8.10 < vGR8.10.179 Version: 8.00 < vGR8.00.165 Version: 7.90 < vGR7.90.1038 |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T13:37:54.194Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16097" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "Command Centre", "vendor": "Gallagher", "versions": [ { "lessThanOrEqual": "vGR7.80", "status": "affected", "version": "unspecified", "versionType": "custom" }, { "lessThan": "vCR8.20.200221b", "status": "affected", "version": "vCR8.20", "versionType": "custom" }, { "lessThan": "vGR8.10.179", "status": "affected", "version": "8.10", "versionType": "custom" }, { "lessThan": "vGR8.00.165", "status": "affected", "version": "8.00", "versionType": "custom" }, { "lessThan": "vGR7.90.1038", "status": "affected", "version": "7.90", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "value": "Matthew Daley of Aura Information Security" } ], "descriptions": [ { "lang": "en", "value": "On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "PHYSICAL", "availabilityImpact": "NONE", "baseScore": 7.3, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N", "version": "3.1" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-522", "description": "CWE-522 Insufficiently Protected Credentials", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2020-09-15T13:19:56", "orgId": "0c426f27-3ee1-4eff-be88-288d5a1822bc", "shortName": "Gallagher" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16097" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 0.0.9" }, "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "disclosures@gallagher.com", "ID": "CVE-2020-16097", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Command Centre", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "vCR8.20", "version_value": "vCR8.20.200221b" }, { "version_affected": "\u003c", "version_name": "8.10", "version_value": "vGR8.10.179" }, { "version_affected": "\u003c", "version_name": "8.00", "version_value": "vGR8.00.165" }, { "version_affected": "\u003c", "version_name": "7.90", "version_value": "vGR7.90.1038" }, { "version_affected": "\u003c=", "version_value": "vGR7.80" } ] } } ] }, "vendor_name": "Gallagher" } ] } }, "credit": [ { "lang": "eng", "value": "Matthew Daley of Aura Information Security" } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers." } ] }, "generator": { "engine": "Vulnogram 0.0.9" }, "impact": { "cvss": { "attackComplexity": "LOW", "attackVector": "PHYSICAL", "availabilityImpact": "NONE", "baseScore": 7.3, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-522 Insufficiently Protected Credentials" } ] } ] }, "references": { "reference_data": [ { "name": "https://security.gallagher.com/Security-Advisories/CVE-2020-16097", "refsource": "MISC", "url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16097" } ] }, "source": { "discovery": "EXTERNAL" } } } }, "cveMetadata": { "assignerOrgId": "0c426f27-3ee1-4eff-be88-288d5a1822bc", "assignerShortName": "Gallagher", "cveId": "CVE-2020-16097", "datePublished": "2020-09-15T13:19:56", "dateReserved": "2020-07-28T00:00:00", "dateUpdated": "2024-08-04T13:37:54.194Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2020-16097\",\"sourceIdentifier\":\"disclosures@gallagher.com\",\"published\":\"2020-09-15T14:15:13.753\",\"lastModified\":\"2024-11-21T05:06:46.277\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.\"},{\"lang\":\"es\",\"value\":\"En controladores que ejecutan versiones desde v8.20 anteriores a vCR8.20.200221b (distribuido en versi\u00f3n v8.20.1093(MR2)), versiones v8.10 anteriores a vGR8.10.179 (distribuido en versi\u00f3n v8.10.1211(MR5)), versiones v8.00 anteriores a vGR8 .00.165 (distribuido en versi\u00f3n v8.00.1228(MR6)), versiones v7.90 anteriores a vGR7.90.165 (distribuido en v7.90.1038(MRX)), versiones v7.80 o anteriores, es posible recuperar las claves del sitio usadas para proteger MIFARE Plus y Desfire por medio de puertos de depuraci\u00f3n en lectores de la Serie T\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"disclosures@gallagher.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N\",\"baseScore\":7.3,\"baseSeverity\":\"HIGH\",\"attackVector\":\"PHYSICAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"CHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":0.9,\"impactScore\":5.8},{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\",\"baseScore\":4.6,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"PHYSICAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":0.9,\"impactScore\":3.6}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:L/AC:L/Au:N/C:P/I:N/A:N\",\"baseScore\":2.1,\"accessVector\":\"LOCAL\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"LOW\",\"exploitabilityScore\":3.9,\"impactScore\":2.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"disclosures@gallagher.com\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-522\"}]},{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"NVD-CWE-noinfo\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"7.90\",\"versionEndExcluding\":\"7.90.1038\",\"matchCriteriaId\":\"EF8D6403-45A4-42BD-AB15-AC90C5580356\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"8.00\",\"versionEndExcluding\":\"8.00.1228\",\"matchCriteriaId\":\"8AF24E0D-FEF8-4814-A689-50869362C70A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"8.10\",\"versionEndExcluding\":\"8.10.1211\",\"matchCriteriaId\":\"55BB8603-0AAE-49A3-B127-374F24C498DE\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"8.20\",\"versionEndExcluding\":\"8.20.1093\",\"matchCriteriaId\":\"9B4EE99E-7138-4228-8792-D4292507157F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:7.90.1038:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"37CD3909-D0B6-4DC7-94EB-0C6F73E37172\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:8.00.1228:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"B5A79B43-E943-44E2-B13A-64F955518C8F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:8.10.1211:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"E672F2DB-6C4D-4549-977C-F4EDBCC461E3\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:gallagher:command_centre:8.20.1093:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"4E4EBA1D-3F39-4FCA-B7A1-E28A65C1811F\"}]}]}],\"references\":[{\"url\":\"https://security.gallagher.com/Security-Advisories/CVE-2020-16097\",\"source\":\"disclosures@gallagher.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://security.gallagher.com/Security-Advisories/CVE-2020-16097\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]}]}}" } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…