CVE-2024-21815

CRITICAL

Gallagher Command Centre < 8.60 - Insufficiently Protected Credentials

Title source: rule

Description

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

Scores

CVSS v3 9.1
EPSS 0.0010
EPSS Percentile 27.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Classification

CWE
CWE-522
Status published

Affected Products (1)

gallagher/command_centre < 8.60

Timeline

Published Mar 05, 2024
Tracked Since Feb 18, 2026