LOW · 2.4

CVE-2023-41967

Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical ac...

Vulnerability Description

Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages. This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.

CVSS Score

2.4

LOW

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GallagherController 6000 Firmware<= 8.60
GallagherController 6000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-41967?

CVE-2023-41967 is a vulnerability with a CVSS score of 2.4 (LOW). Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical ac...

How severe is CVE-2023-41967?

CVE-2023-41967 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-41967?

Check the references section above for vendor advisories and patch information. Affected products include: Gallagher Controller 6000 Firmware, Gallagher Controller 6000.