Incomplete Comparison Vulnerability in Gallagher Controller
CVE-2021-23146
7.1HIGH
What is CVE-2021-23146?
An incomplete comparison vulnerability within the Gallagher Controller may allow an unauthorized attacker to bypass Personal Identity Verification (PIV) processes, compromising the security of the system. This flaw affects multiple versions of the Gallagher Command Centre software, specifically those prior to designated update releases, potentially enabling attackers to exploit the affected systems without proper verification protocols.
Affected Version(s)
Command Center 8.40 prior to 8.40.1888 (MR3)
Command Center 8.30 prior to 8.30.1359 (MR3)
Command Center 8.20 prior to 8.20.1259 (MR5)