nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-46406 CVE-2025-46406
MEDIUM
Record summary
CVE-2025-46406 has a selected CVSS score of 5.6 (medium).
Description
A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects Command Centre Server: 9.30 prior to 9.30.1874 (MR1), 9.20 prior to 9.20.2337 (MR3), 9.10 prior to 9.10.3194 (MR6), 9.00 prior to 9.00.3371 (MR7), all versions of 8.90 and prior.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Command Centre ServerBrowse Gallagher / Command Centre ServerDefault status: unaffected | CVE List | Through 8.90 | affected |
| 9.30 to < 9.30.1874 (MR1) | affected | ||
| 9.20 to < 9.20.2337 (MR3) | affected | ||
| 9.10 to < 9.10.3194 (MR6) | affected | ||
| 9.00 to < 9.00.3371 (MR7) | affected |
References
2security.gallagher.com
https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-46406