Unquoted Service Path Vulnerability in Gallagher Command Centre
CVE-2021-23197

5.2MEDIUM

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
18 November 2021

What is CVE-2021-23197?

An unquoted service path vulnerability in Gallagher Command Centre enables an unprivileged user to execute arbitrary code under the context of the service account. This flaw impacts versions prior to 8.50.2048, posing a significant risk to the integrity and security of the system. Users are strongly advised to upgrade to secure versions to mitigate potential exploitation.

Affected Version(s)

Command Centre 8.50 < 8.50.2048 (MR3)

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-23197 : Unquoted Service Path Vulnerability in Gallagher Command Centre