Improper Encoding in Gallagher Command Centre Server Affects Configuration Management
CVE-2021-23205

8.1HIGH

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
11 June 2021

What is CVE-2021-23205?

An improper encoding or escaping vulnerability in Gallagher Command Centre Server allows Command Centre Operators to manipulate the configuration settings of Controllers and other hardware items beyond their authorized privileges. This situation can potentially lead to unauthorized actions within the system, making it crucial for users to update to the secured versions to mitigate associated risks. The affected software versions include Gallagher Command Centre 8.40 prior to 8.40.1888 (MR3), 8.30 prior to 8.30.1359 (MR3), 8.20 prior to 8.20.1259 (MR5), and all versions of 8.10 and earlier.

Affected Version(s)

Command Centre <= 8.10

Command Centre 8.40 < 8.40.1888 (MR3)

Command Centre 8.30 < 8.30.1359 (MR3)

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.