First published: Thu Nov 18 2021(Updated: )
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <=8.00 | |
Gallagher Command Centre | >=8.10<8.10.1284 | |
Gallagher Command Centre | >=8.20<8.20.1259 | |
Gallagher Command Centre | >=8.30<8.30.1359 | |
Gallagher Command Centre | >=8.40<8.40.1888 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23146 has a high severity rating as it allows attackers to bypass PIV verification.
To fix CVE-2021-23146, upgrade Gallagher Command Centre to version 8.40.1888 or later, 8.30.1359 or later, or 8.20.1259 or later.
Organizations using Gallagher Command Centre versions prior to 8.40.1888, 8.30.1359, and 8.20.1259 are affected by CVE-2021-23146.
CVE-2021-23146 is classified as an Incomplete Comparison with Missing Factors vulnerability.
If exploited, CVE-2021-23146 allows an attacker to bypass important PIV verification processes.