CVE-2023-41967
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2023
Last modified:
05/01/2024
Description
<br />
Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller&#39;s default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages. <br />
<br />
This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.<br />
<br />
<br />
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:* | 8.60 (including) | |
| cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:* | 8.70 (including) | 8.70.231204a (excluding) |
| cpe:2.3:h:gallagher:controller_6000:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



