CVE-2019-15294
Last modified
CVE-2019-15294 is a vulnerability of currently unknown severity. An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gallagher | Command Centre | >= 8.10, < 8.10.1092 |
References
- https://security.gallagher.com/CVE-2019-15294Vendor Advisory
- https://security.gallagher.com/security-advisoriesVendor Advisory
- https://security.gallagher.com/CVE-2019-15294Vendor Advisory
- https://security.gallagher.com/security-advisoriesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15294?
How severe is CVE-2019-15294?
How do I fix CVE-2019-15294?
Are you affected by CVE-2019-15294?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
