Insufficient Protection of Third-Party DVR Integrations
CVE-2024-21815
What is CVE-2024-21815?
The Gallagher Command Centre is impacted by a vulnerability that allows authenticated but unprivileged users to access insufficiently protected credentials related to third-party DVR integrations. This security flaw arises from a lack of proper safeguards, potentially exposing sensitive information and creating a risk for unauthorized exploitation. Affected versions include Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), and all versions of 8.60 and earlier. Organizations using these versions should consider appropriate measures to mitigate potential risks.
Affected Version(s)
Command Centre Server 0 <= 8.60
Command Centre Server 9.00
Command Centre Server 8.90