CVE-2021-23197

MEDIUM

Gallagher Command Centre <8.50.2048 - RCE

Title source: llm
STIX 2.1

Description

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ;

Scores

CVSS v3 5.2
EPSS 0.0004
EPSS Percentile 13.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-428
Status published
Products (1)
gallagher/command_centre 8.50 - 8.50.2048
Published Nov 18, 2021
Tracked Since Feb 18, 2026