CVE-2024-43690

HIGH

Command Centre Server/Workstations <9.10-8.70 - RCE

Title source: llm
STIX 2.1

Description

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior.

Scores

CVSS v3 8.0
EPSS 0.0309
EPSS Percentile 86.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-829
Status published
Products (5)
Gallagher/Command Centre Server < 8.70
Gallagher/Command Centre Server 8.80 - vEL8.80.1938 (MR6)
Gallagher/Command Centre Server 8.90 - vEL8.90.2155 (MR5)
Gallagher/Command Centre Server 9.00 - vEL9.00.2168 (MR4)
Gallagher/Command Centre Server 9.10 - vEL9.10.1530(MR2)
Published Sep 11, 2024
Tracked Since Feb 18, 2026