Improper Encoding in Gallagher Command Centre Server Affects Configuration Management
CVE-2021-23205
8.1HIGH
What is CVE-2021-23205?
An improper encoding or escaping vulnerability in Gallagher Command Centre Server allows Command Centre Operators to manipulate the configuration settings of Controllers and other hardware items beyond their authorized privileges. This situation can potentially lead to unauthorized actions within the system, making it crucial for users to update to the secured versions to mitigate associated risks. The affected software versions include Gallagher Command Centre 8.40 prior to 8.40.1888 (MR3), 8.30 prior to 8.30.1359 (MR3), 8.20 prior to 8.20.1259 (MR5), and all versions of 8.10 and earlier.
Affected Version(s)
Command Centre <= 8.10
Command Centre 8.40 < 8.40.1888 (MR3)
Command Centre 8.30 < 8.30.1359 (MR3)
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
