CVE-2020-16100
Summary
| CVE | CVE-2020-16100 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-15 14:15:00 UTC |
| Updated | 2020-09-24 17:31:00 UTC |
| Description | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to improper shutdown of closed websocket connections, preventing it from accepting future DCOM websocket (Configuration Client) connections. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier. |
Risk And Classification
Problem Types: CWE-404
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gallagher | Command Centre | All | All | All | All |
| Application | Gallagher | Command Centre | 8.00.1228 | - | All | All |
| Application | Gallagher | Command Centre | 8.10.1211 | - | All | All |
| Application | Gallagher | Command Centre | 8.20.1166 | - | All | All |
| Application | Gallagher | Command Centre | All | All | All | All |
| Application | Gallagher | Command Centre | 8.00.1228 | - | All | All |
| Application | Gallagher | Command Centre | 8.10.1211 | - | All | All |
| Application | Gallagher | Command Centre | 8.20.1166 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-16100 | MISC | security.gallagher.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.