CVE-2023-24590

HIGH

Gallagher Controller 6000 <8.60.231116a - Use After Free

Title source: llm
STIX 2.1

Description

A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

Scores

CVSS v3 7.5
EPSS 0.0015
EPSS Percentile 34.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-134
Status published
Products (1)
gallagher/controller_6000_firmware < 8.50
Published Dec 18, 2023
Tracked Since Feb 18, 2026