CVE-2023-41967
LOW
2,4
Source: [email protected]
Attack Vector: physical
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages.
This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0012
Percentile
0,3th
Updated
EPSS Score Trend (Last 90 Days)
212
Improper Removal of Sensitive Information Before Storage or Transfer
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Files Or Directories
Read Application Data
Applicable Platforms
All platforms may be affected
1272
Sensitive Information Uncleared Before Debug/Power State Transition
StableCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Access Control
Accountability
Authentication
Authorization
Non-Repudiation
Potential Impacts:
Read Memory
Read Application Data
Applicable Platforms
Languages:
Hardware Description Language, Verilog, VHDL
Operating System
Controller 6000 Firmware by Gallagher
Version Range Affected
From
8.70
(inclusive)
To
8.70.231204a
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Controller 6000 Firmware by Gallagher
Version Range Affected
To
8.60
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://security.gallagher.com/Security-Advisories/CVE-2023-41967
https://security.gallagher.com/Security-Advisories/CVE-2023-41967