« Volver al listado

CVE-2020-16101

Estado: ModificadaAlta (7.5)—

It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-16101",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosures@gallagher.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "disclosures@gallagher.com",
      "affectedData": [
        {
          "vendor": "Gallagher",
          "product": "Command Centre",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "7.90"
            },
            {
              "status": "affected",
              "version": "8.20",
              "lessThan": "8.20.1166 (MR3)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.10",
              "lessThan": "8.10.1211 (MR5)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.00",
              "lessThan": "8.00.1228 (MR6)",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-15T14:15:14.097",
  "references": [
    {
      "url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16101",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosures@gallagher.com"
    },
    {
      "url": "https://security.gallagher.com/Security-Advisories/CVE-2020-16101",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosures@gallagher.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-805"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier."
    },
    {
      "lang": "es",
      "value": "Es posible que una conexión websocket DCOM remota no autenticada bloquee el servicio Command Center debido a un acceso al búfer fuera de límites. Las versiones afectadas son v8.20 anterior a v8.20.1166(MR3), v8.10 anterior a v8.10.1211(MR5), v8.00 anterior a v8.00.1228(MR6), todas las versiones desde 7.90 y anteriores"
    }
  ],
  "lastModified": "2026-06-17T02:57:43.303",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AF24E0D-FEF8-4814-A689-50869362C70A",
              "versionEndExcluding": "8.00.1228",
              "versionStartIncluding": "8.00"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55BB8603-0AAE-49A3-B127-374F24C498DE",
              "versionEndExcluding": "8.10.1211",
              "versionStartIncluding": "8.10"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE7DBECA-3C79-4346-AB66-B7538B230FE7",
              "versionEndExcluding": "8.20.1166",
              "versionStartIncluding": "8.20"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:8.00.1228:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5A79B43-E943-44E2-B13A-64F955518C8F"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:8.10.1211:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E672F2DB-6C4D-4549-977C-F4EDBCC461E3"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:8.20.1166:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3DACA47B-78DA-4ED5-A15B-04556FA11865"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosures@gallagher.com"
}