CVE-2023-41967
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Published Dec 18, 2023
Updated: Jan 5, 2024
CWE ID 1272
CWE ID 212
Summary
CVE-2023-41967 is a vulnerability affecting the Gallagher Controller 6000 version 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), and v8.60 or earlier. An attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller can exploit this issue by viewing sensitive information that is not properly cleared after a debug or power state transition. This vulnerability could allow the attacker to gain unauthorized access to the Controller's configuration through the diagnostic web pages.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Gallagher