CVE-2020-16100
Estado: ModificadaAlta (7.5)—
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configuration Client) connections. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.04%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-404
- CWE-404
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-16100",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosures@gallagher.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "disclosures@gallagher.com",
"affectedData": [
{
"vendor": "Gallagher",
"product": "Command Centre",
"versions": [
{
"status": "affected",
"version": "unspecified",
"versionType": "custom",
"lessThanOrEqual": "7.90"
},
{
"status": "affected",
"version": "8.20",
"lessThan": "8.20.1166 (MR3)",
"versionType": "custom"
},
{
"status": "affected",
"version": "8.10",
"lessThan": "8.10.1211 (MR5)",
"versionType": "custom"
},
{
"status": "affected",
"version": "8.00",
"lessThan": "8.00.1228 (MR6)",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-09-15T14:15:13.987",
"references": [
{
"url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16100",
"tags": [
"Vendor Advisory"
],
"source": "disclosures@gallagher.com"
},
{
"url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16100",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosures@gallagher.com",
"description": [
{
"lang": "en",
"value": "CWE-404"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-404"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configuration Client) connections. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier."
},
{
"lang": "es",
"value": "Es posible que una conexión websocket DCOM remota no autenticada bloquee el hilo (o subproceso) del websocket DCOM del servicio Command Center debido a un cierre inapropiado de las conexiones websocket cerradas, impidiendo aceptar futuras conexiones websocket DCOM (Configuration Client). Las versiones afectadas son v8.20 anterior a v8.20.1166(MR3), v8.10 anterior a v8.10.1211(MR5), v8.00 anterior a v8.00.1228(MR6), todas las versiones de 7.90 y anteriores"
}
],
"lastModified": "2026-06-17T02:57:43.177",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8AF24E0D-FEF8-4814-A689-50869362C70A",
"versionEndExcluding": "8.00.1228",
"versionStartIncluding": "8.00"
},
{
"criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55BB8603-0AAE-49A3-B127-374F24C498DE",
"versionEndExcluding": "8.10.1211",
"versionStartIncluding": "8.10"
},
{
"criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DE7DBECA-3C79-4346-AB66-B7538B230FE7",
"versionEndExcluding": "8.20.1166",
"versionStartIncluding": "8.20"
},
{
"criteria": "cpe:2.3:a:gallagher:command_centre:8.00.1228:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5A79B43-E943-44E2-B13A-64F955518C8F"
},
{
"criteria": "cpe:2.3:a:gallagher:command_centre:8.10.1211:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E672F2DB-6C4D-4549-977C-F4EDBCC461E3"
},
{
"criteria": "cpe:2.3:a:gallagher:command_centre:8.20.1166:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DACA47B-78DA-4ED5-A15B-04556FA11865"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "disclosures@gallagher.com"
}