Bypass of Server-Side Security in Gallagher Command Centre Software
CVE-2023-23570

5.4MEDIUM

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
18 December 2023

What is CVE-2023-23570?

A vulnerability exists in Gallagher Command Centre software that allows client-side enforcement to be bypassed, potentially leading to invalid configuration settings with undefined behavior. This issue affects all versions of Gallagher Command Centre 8.80 and earlier, and as well as version 8.90 prior to vEL8.90.1620 (MR2), posing a security risk to affected deployments.

Affected Version(s)

Command Centre 0 <= 8.80

Command Centre 8.90 <= 8.90.1620 (MR2)

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.