CVE-2023-41967

Published: Dic 18, 2023 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2023-46426 Aliases: GSD-2023-41967
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,4
Attack Vector: physical
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available


Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages.

This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0012
Percentile
0,3th
Updated

EPSS Score Trend (Last 90 Days)

212

Improper Removal of Sensitive Information Before Storage or Transfer

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Files Or Directories Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
1272

Sensitive Information Uncleared Before Debug/Power State Transition

Stable
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability Access Control Accountability Authentication Authorization Non-Repudiation
Potential Impacts:
Read Memory Read Application Data
Applicable Platforms
Languages: Hardware Description Language, Verilog, VHDL
View CWE Details
Operating System

Controller 6000 Firmware by Gallagher

Version Range Affected
From 8.70 (inclusive)
To 8.70.231204a (exclusive)
cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Controller 6000 Firmware by Gallagher

Version Range Affected
To 8.60 (inclusive)
cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://security.gallagher.com/Security-Advisories/CVE-2023-41967
https://security.gallagher.com/Security-Advisories/CVE-2023-41967