CVE-2020-16100 describes a vulnerability in Gallagher Command Centre versions prior to v8.20.1166 (MR3), v8.10.1211 (MR5), v8.00.1228 (MR6), and all versions of 7.90 and earlier. An unauthenticated remote DCOM websocket connection can crash the Command Centre service's DCOM websocket thread due to improper handling of closed connections. This prevents the service from accepting new DCOM websocket connections, leading to a denial of service. The vulnerability has a CVSS v3.1 score of 7.5 (HIGH), indicating it can be exploited remotely without authentication and with low attack complexity, resulting in high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.00, < 8.00.1228CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
>= 8.10, < 8.10.1211CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
>= 8.20, < 8.20.1166CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
8.00.1228CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:8.00.1228:-:*:*:*:*:*:* | ||
8.10.1211CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:8.10.1211:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.