Vulnerability Description
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gallagher | Command Centre | <= 8.60 |
Related Weaknesses (CWE)
References
- https://security.gallagher.com/Security-Advisories/CVE-2024-21815Vendor Advisory
- https://security.gallagher.com/Security-Advisories/CVE-2024-21815Vendor Advisory
FAQ
What is CVE-2024-21815?
CVE-2024-21815 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Co...
How severe is CVE-2024-21815?
CVE-2024-21815 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-21815?
Check the references section above for vendor advisories and patch information. Affected products include: Gallagher Command Centre.