CVE-2024-21815
CRITICALGallagher Command Centre < 8.60 - Insufficiently Protected Credentials
Title source: ruleDescription
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
Scores
CVSS v3
9.1
EPSS
0.0010
EPSS Percentile
27.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Classification
CWE
CWE-522
Status
published
Affected Products (1)
gallagher/command_centre
< 8.60
Timeline
Published
Mar 05, 2024
Tracked Since
Feb 18, 2026