Incomplete Comparison Vulnerability in Gallagher Controller
CVE-2021-23146

7.1HIGH

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
18 November 2021

What is CVE-2021-23146?

An incomplete comparison vulnerability within the Gallagher Controller may allow an unauthorized attacker to bypass Personal Identity Verification (PIV) processes, compromising the security of the system. This flaw affects multiple versions of the Gallagher Command Centre software, specifically those prior to designated update releases, potentially enabling attackers to exploit the affected systems without proper verification protocols.

Affected Version(s)

Command Center 8.40 prior to 8.40.1888 (MR3)

Command Center 8.30 prior to 8.30.1359 (MR3)

Command Center 8.20 prior to 8.20.1259 (MR5)

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.