First published: Fri Jun 11 2021(Updated: )
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3).
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | >=8.40<8.40.1888 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23211 is rated as a medium severity vulnerability due to its potential exposure of sensitive encryption keys.
To address CVE-2021-23211, upgrade to Gallagher Command Centre version 8.40.1888 or later.
CVE-2021-23211 can lead to the discovery of cloud end-to-end encryption keys stored in server memory, compromising data security.
CVE-2021-23211 affects Gallagher Command Centre versions prior to 8.40.1888.
There are no documented workarounds for CVE-2021-23211; upgrading to the fixed version is the recommended solution.