- EPSS 3.09%
- Veröffentlicht 11.09.2024 05:15:02
- Zuletzt bearbeitet 11.09.2024 16:26:11
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9...
CVE-2024-23194
- EPSS 0.04%
- Veröffentlicht 11.07.2024 03:15:02
- Zuletzt bearbeitet 21.11.2024 08:57:10
Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. This issue affects: Gallagher Command Centre v9.10 prior to vEL9.10.1268 (M...
CVE-2024-21838
- EPSS 0.32%
- Veröffentlicht 05.03.2024 03:15:06
- Zuletzt bearbeitet 10.02.2025 22:33:35
Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre ...
CVE-2024-21815
- EPSS 0.1%
- Veröffentlicht 05.03.2024 03:15:06
- Zuletzt bearbeitet 10.02.2025 22:36:41
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.9...
CVE-2023-46686
- EPSS 0.08%
- Veröffentlicht 18.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:04
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Servi...
CVE-2023-23584
- EPSS 0.17%
- Veröffentlicht 18.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:28
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL...
CVE-2023-23576
- EPSS 0.08%
- Veröffentlicht 18.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:27
Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when competencies are used in the access decision. This issue affects: Gallagher...
CVE-2023-23570
- EPSS 0.04%
- Veröffentlicht 18.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:26
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command Centre 8.90 prior to vEL8.90.1620 (MR2), all versions ...
CVE-2023-22439
- EPSS 0.06%
- Veröffentlicht 18.12.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:44:48
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Contr...
CVE-2023-23568
- EPSS 0.07%
- Veröffentlicht 25.07.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:26
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL 8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2...