CVE-2023-41967
Last modified
CVE-2023-41967 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages. This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier. . EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web pages. This issue affects: Gallagher Controller 6000 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), v8.60 or earlier.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gallagher | Controller 6000 Firmware | <= 8.60 |
| Gallagher | Controller 6000 Firmware | >= 8.70, < 8.70.231204a |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41967?
How severe is CVE-2023-41967?
How do I fix CVE-2023-41967?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-41961Uncontrolled search path in some Intel(R) GPA software befor…7.8
- CVE-2023-41962Cross-site scripting vulnerability in Credit Card Payment Se…6.1
- CVE-2023-41963Denial-of-service (DoS) vulnerability exists in FTP service …7.5
- CVE-2023-41964 The BIG-IP and BIG-IQ systems do not encrypt some sensitive…6.5
- CVE-2023-41965Sending some requests in the web application of the vulnerab…7.5
- CVE-2023-41966 The application suffers from a privilege escalation vulne…8.8
- CVE-2023-41968This issue was addressed with improved validation of symlink…5.5
- CVE-2023-41969An arbitrary file deletion in ZSATrayManager where it protec…7.1
- CVE-2023-4197Improper input validation in Dolibarr ERP CRM <= v18.0.1 fai…8.8
- CVE-2023-41970An Improper Validation of Integrity Check Value vulnerabilit…7.8
- CVE-2023-41971An Improper Link Resolution Before File Access ('Link Follow…7.8
- CVE-2023-41972In some rare cases, there is a password type validation miss…7.8
Are you affected by CVE-2023-41967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
