CVE-2019-19802
Summary
| CVE | CVE-2019-19802 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-17 02:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OPCUA can view all data that would be replicated in a multi-server setup without privilege checks being applied. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gallagher | Command Centre | All | All | All | All |
| Application | Gallagher | Command Centre | 7.80.960 | - | All | All |
| Application | Gallagher | Command Centre | 7.90.991 | - | All | All |
| Application | Gallagher | Command Centre | 8.00.1161 | - | All | All |
| Application | Gallagher | Command Centre | 8.10.1134 | - | All | All |
| Application | Gallagher | Command Centre | All | All | All | All |
| Application | Gallagher | Command Centre | 7.80.960 | - | All | All |
| Application | Gallagher | Command Centre | 7.90.991 | - | All | All |
| Application | Gallagher | Command Centre | 8.00.1161 | - | All | All |
| Application | Gallagher | Command Centre | 8.10.1134 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-19802 | CONFIRM | security.gallagher.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.