CVE-2020-16097: Gallagher Command Centre

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.

Affected products

  • Gallagher Command Centre: from 7.90, before 7.90.1038 (fixed in 7.90.1038); from 8.00, before 8.00.1228 (fixed in 8.00.1228); from 8.10, before 8.10.1211 (fixed in 8.10.1211); from 8.20, before 8.20.1093 (fixed in 8.20.1093); version 7.90.1038 only; version 8.00.1228 only; …

Published 2020-09-15. Last modified 2026-06-17.