PT-2019-14036 · Microsoft+1 · Windows+1
Published
2019-08-28
·
Updated
2020-08-24
·
CVE-2019-15294
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gallagher Command Centre version 8.10 before 8.10.1092(MR2)
Description
An issue was discovered where the Windows username and password for a custom service account are logged in cleartext to the Command centre.log file upon an upgrade, if the visitor management service is installed.
Recommendations
For Gallagher Command Centre version 8.10 before 8.10.1092(MR2), update to version 8.10.1092(MR2) or later to resolve the issue. As a temporary workaround, consider restricting access to the Command centre.log file to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gallagher Command Centre
Windows