Improper Authorization Issue in Gallagher Command Centre Server
CVE-2021-23140

9.9CRITICAL

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
11 June 2021

What is CVE-2021-23140?

An improper authorization vulnerability in the Gallagher Command Centre Server allows an unauthorized Command Centre Operator to modify command line macros. This can potentially lead to unauthorized changes in system operations, increasing security risks across affected versions. Those using Gallagher Command Centre 8.40 versions before 8.40.1888 (MR3), 8.30 versions before 8.30.1359 (MR3), 8.20 versions before 8.20.1259 (MR5), as well as version 8.10 and earlier, should take immediate action to mitigate their exposure to this vulnerability.

Affected Version(s)

Command Centre <= 8.10

Command Centre 8.40 < 8.40.1888 (MR3)

Command Centre 8.30 < 8.30.1359 (MR3)

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-23140 : Improper Authorization Issue in Gallagher Command Centre Server