---
cve: "CVE-2026-20801"
severity: "MEDIUM"
cvss: 5.6
epss: "0.1%"
vendor: "Gallagher"
kev: false
exploited: false
published: "2026-03-03 03:15:54"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-22T00:28:15+02:00"
---

# CVE-2026-20801

> 5.6 MEDIUM

## Beschreibung

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations allows unprivileged users with local network access to view live video streams. 

 

This issue affects all versions of Gallagher NxWitness VMS integration prior to 9.10.017 and Gallagher Hanwha VMS integration prior to 9.10.025.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Gering | warn |

## Schwachstellen-Klasse

- **CWE-319** — Cleartext Transmission of Sensitive Information
  The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

## Angriffsmuster (CAPEC)

- [CAPEC-65 — Sniff Application Code](https://capec.mitre.org/data/definitions/65.html) _(Severity: High)_
- [CAPEC-102 — Session Sidejacking](https://capec.mitre.org/data/definitions/102.html) _(Severity: High)_
- [CAPEC-117 — Interception](https://capec.mitre.org/data/definitions/117.html) _(Severity: Medium)_
- [CAPEC-383 — Harvesting Information via API Event Monitoring](https://capec.mitre.org/data/definitions/383.html) _(Severity: Low)_
- [CAPEC-477 — Signature Spoofing by Mixing Signed and Unsigned Content](https://capec.mitre.org/data/definitions/477.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1040 — Network Sniffing](https://attack.mitre.org/techniques/T1040/)
- [T1056.004 — Input Capture: Credential API Hooking](https://attack.mitre.org/techniques/T1056/004/)

## Referenzen

- <https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20801>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-20801) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
