CVE-2023-41967

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2023
Last modified:
05/01/2024

Description

<br /> Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller&amp;#39;s default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages. <br /> <br /> This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:* 8.60 (including)
cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:* 8.70 (including) 8.70.231204a (excluding)
cpe:2.3:h:gallagher:controller_6000:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools