Ad

CVE-2026-20801

MEDIUM CVSS 3.1: 5.6 EPSS 0.02%
Updated Mar 03, 2026
Cleartext
Parameter Value
CVSS 5.6 (MEDIUM)
Affected Versions before 9.10.017
Type CWE-319 (Cleartext Transmission)
Vendor Cleartext
Public PoC No

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1