8.8
CVE-2023-24590
- EPSS 0.15%
- Veröffentlicht 18.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:48:11
- Quelle disclosures@gallagher.com
- CVE-Watchlists
- Unerledigt
A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gallagher ≫ Controller 6000 Firmware Version <= 8.50
Gallagher ≫ Controller 6000 Firmware Version >= 8.60 < 8.60.231116a
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.356 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| disclosures@gallagher.com | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.