CVE-2020-16097

MEDIUMCVSS 4.6/10EPSS 0.31%

Last modified

CVE-2020-16097 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.

Metrics

CVSS 3.1
4.6/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.31%

22.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GallagherCommand Centre>= 7.90, < 7.90.1038
GallagherCommand Centre>= 8.00, < 8.00.1228
GallagherCommand Centre>= 8.10, < 8.10.1211
GallagherCommand Centre>= 8.20, < 8.20.1093
GallagherCommand Centre7.90.1038
GallagherCommand Centre8.00.1228
GallagherCommand Centre8.10.1211
GallagherCommand Centre8.20.1093

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-16097?
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.
How severe is CVE-2020-16097?
CVE-2020-16097 has a CVSS score of 4.6/10 (MEDIUM severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2020-16097?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-16097?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST