Vulnerability Description
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gallagher | Controller 6000 Firmware | < 8.50.230201a |
| Gallagher | Controller 6000 | - |
Related Weaknesses (CWE)
References
- https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-24584Vendor Advisory
- https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-24584Vendor Advisory
FAQ
What is CVE-2023-24584?
CVE-2023-24584 is a vulnerability with a CVSS score of 7.5 (HIGH). Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a,...
How severe is CVE-2023-24584?
CVE-2023-24584 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-24584?
Check the references section above for vendor advisories and patch information. Affected products include: Gallagher Controller 6000 Firmware, Gallagher Controller 6000.