Unsafe Inclusion of Functionality from Untrusted Control Sphere Could Lead to Remote Code Execution
CVE-2024-43690

8HIGH

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
11 September 2024

What is CVE-2024-43690?

The vulnerability arises from the inclusion of functionality from an untrusted control sphere in Gallagher's Command Centre Server and Workstations. This flaw may enable an attacker to execute arbitrary code remotely, potentially compromising the integrity and security of the affected systems. Specific versions of the software are vulnerable, including several prior versions of Command Centre Server and Workstations. Addressing this vulnerability is crucial to prevent exploitation and ensure the security of operations reliant on these systems.

Affected Version(s)

Command Centre Server 0 <= 8.70

Command Centre Server 0 <= 8.70

Command Centre Server 9.10

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.