CVE-2020-16097
Summary
| CVE | CVE-2020-16097 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-15 14:15:00 UTC |
| Updated | 2020-09-22 17:12:00 UTC |
| Description | On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gallagher | Command Centre | All | All | All | All |
| Application | Gallagher | Command Centre | 7.90.1038 | - | All | All |
| Application | Gallagher | Command Centre | 8.00.1228 | - | All | All |
| Application | Gallagher | Command Centre | 8.10.1211 | - | All | All |
| Application | Gallagher | Command Centre | 8.20.1093 | - | All | All |
| Application | Gallagher | Command Centre | All | All | All | All |
| Application | Gallagher | Command Centre | 7.90.1038 | - | All | All |
| Application | Gallagher | Command Centre | 8.00.1228 | - | All | All |
| Application | Gallagher | Command Centre | 8.10.1211 | - | All | All |
| Application | Gallagher | Command Centre | 8.20.1093 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-16097 | MISC | security.gallagher.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Matthew Daley of Aura Information Security
There are currently no legacy QID mappings associated with this CVE.