Insufficient Protection of Third-Party DVR Integrations
CVE-2024-21815

6.5MEDIUM

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
5 March 2024

What is CVE-2024-21815?

The Gallagher Command Centre is impacted by a vulnerability that allows authenticated but unprivileged users to access insufficiently protected credentials related to third-party DVR integrations. This security flaw arises from a lack of proper safeguards, potentially exposing sensitive information and creating a risk for unauthorized exploitation. Affected versions include Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), and all versions of 8.60 and earlier. Organizations using these versions should consider appropriate measures to mitigate potential risks.

Affected Version(s)

Command Centre Server 0 <= 8.60

Command Centre Server 9.00

Command Centre Server 8.90

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.