Impact
The vulnerability is caused by an uncaught exception (CWE‑248) that occurs when an authenticated operator sends specific requests to the T‑20 Reader, leading to a system restart and a temporary denial of service. It does not provide code execution, privilege escalation, or other more severe consequences, limiting the impact to brief loss of availability.
Affected Systems
Gallagher T‑20 Readers that run Command Centre versions 9.50 and earlier (up to earlier (up to 9.40.3130), 930.3983), 9.20 and earlier (up to 9.20.4349), and all releases of 9.10 and prior are affected.
Risk and Exploitability
The CVSS score of 2.7 reflects low severity, and the EPSS score of less than 1% indicates that exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog. An attacker must be an authenticated operator with sufficient privileges to issue restart commands, meaning the threat is confined to environments where such permissions are granted.
OpenCVE Enrichment