Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users.
This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19427 | Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Feb 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gallagher
Gallagher command Centre |
|
| CPEs | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gallagher
Gallagher command Centre |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2024-08-01T22:27:36.314Z
Reserved: 2024-02-05T04:16:48.019Z
Link: CVE-2024-21815
Updated: 2024-08-01T22:27:36.314Z
Status : Analyzed
Published: 2024-03-05T03:15:06.060
Modified: 2025-02-10T22:36:41.683
Link: CVE-2024-21815
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD