First published: Fri Jan 17 2020(Updated: )
In Gallagher Command Centre Server versions of v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an unprivileged but authenticated user is able to perform a backup of the Command Centre databases.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <7.70 | |
Gallagher Command Centre | >=7.80<7.80.960 | |
Gallagher Command Centre | >=7.90<7.90.991 | |
Gallagher Command Centre | >=8.00<8.00.1161 | |
Gallagher Command Centre | >=8.10<8.10.1134 | |
Gallagher Command Centre | =7.80.960 | |
Gallagher Command Centre | =7.90.991 | |
Gallagher Command Centre | =8.00.1161 | |
Gallagher Command Centre | =8.10.1134 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19801 is classified as a high severity vulnerability due to the risk of unprivileged authenticated users being able to access sensitive database backups.
To fix CVE-2019-19801, upgrade the Gallagher Command Centre to versions v8.10.1134 or later, v8.00.1161 or later, v7.90.991 or later, v7.80.960 or later, or v7.70.
CVE-2019-19801 affects users of Gallagher Command Centre versions earlier than v8.10.1134, v8.00.1161, v7.90.991, v7.80.960, and v7.70.
CVE-2019-19801 allows an unprivileged but authenticated user to perform unauthorized backups of the Command Centre databases.
CVE-2019-19801 is considered a local vulnerability as it requires authenticated access to exploit.