CVE-2024-21815

CRITICAL

Gallagher Command Centre < 8.60 - Authenticated Insufficiently Protected Credentials

Title source: llm
STIX 2.1

Description

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0033
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (1)
gallagher/command_centre < 8.60
Published Mar 05, 2024
Tracked Since Feb 18, 2026