Description
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); version 8.00 and prior versions.
Scores
CVSS v3
8.8
EPSS
0.0205
EPSS Percentile
83.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-843
CWE-704
Status
published
Products (4)
gallagher/command_centre
8.10.1211 (2 CPE variants)
gallagher/command_centre
8.20.1166 (2 CPE variants)
gallagher/command_centre
8.30.1236 (2 CPE variants)
gallagher/command_centre
< 8.00
Published
Dec 14, 2020
Tracked Since
Feb 18, 2026