First published: Thu Nov 18 2021(Updated: )
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ;
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | >=8.50<8.50.2048 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23197 is a high-severity vulnerability that allows unprivileged users to execute arbitrary code.
To fix CVE-2021-23197, upgrade Gallagher Command Centre to version 8.50.2048 or later.
CVE-2021-23197 affects Gallagher Command Centre versions prior to 8.50.2048.
CVE-2021-23197 is an unquoted service path vulnerability.
An attacker exploiting CVE-2021-23197 can execute arbitrary code as the user running the Gallagher Controller Service.