CVE-2024-21815

9.1CRITICAL

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Co

Veröffentlicht: 3/5/2024Aktualisiert: 2/10/2025

Beschreibung

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

KI-AnalyseKI-gestützt

Betroffene Produkte

gallaghercommand_centre
gallaghercommand_centre
gallaghercommand_centre
gallaghercommand_centre
gallaghercommand_centre

Referenzen