Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted. Mitigation: For sites concerned about exposure, the recommended action is to change the Service Account password. They can also delete any installer log files, usually found in %programdata%\Gallagher\Command Centre.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Gallagher | Active Directory Sync | >= 0, < 9.10.05CNA affecteddefault affected | |
| Gallagher | Cardholder Sync Utility | >= 0, < 9.30.104CNA affecteddefault affected | |
| Gallagher | Diagnostics Service | >= 0, < 2.0.9CNA affecteddefault affected | |
| Gallagher | Elevator Service | >= 0, < 10.0.8CNA affecteddefault affected | |
| Gallagher | Encoding Kiosk Application | >= 0, < 9.60.10CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.