Bypass of Server-Side Security in Gallagher Command Centre Software
CVE-2023-23570
5.4MEDIUM
What is CVE-2023-23570?
A vulnerability exists in Gallagher Command Centre software that allows client-side enforcement to be bypassed, potentially leading to invalid configuration settings with undefined behavior. This issue affects all versions of Gallagher Command Centre 8.80 and earlier, and as well as version 8.90 prior to vEL8.90.1620 (MR2), posing a security risk to affected deployments.
Affected Version(s)
Command Centre 0 <= 8.80
Command Centre 8.90 <= 8.90.1620 (MR2)
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
