Unsafe Inclusion of Functionality from Untrusted Control Sphere Could Lead to Remote Code Execution
CVE-2024-43690
8HIGH
What is CVE-2024-43690?
The vulnerability arises from the inclusion of functionality from an untrusted control sphere in Gallagher's Command Centre Server and Workstations. This flaw may enable an attacker to execute arbitrary code remotely, potentially compromising the integrity and security of the affected systems. Specific versions of the software are vulnerable, including several prior versions of Command Centre Server and Workstations. Addressing this vulnerability is crucial to prevent exploitation and ensure the security of operations reliant on these systems.
Affected Version(s)
Command Centre Server 0 <= 8.70
Command Centre Server 0 <= 8.70
Command Centre Server 9.10
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
