First published: Mon Dec 18 2023(Updated: )
A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Gallagher Controller 6000 Firmware | <=8.50 | |
Gallagher Controller 6000 Firmware | >=8.60<8.60.231116a | |
Gallagher Controller 6000 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24590 is categorized as a high-severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2023-24590, users should upgrade the Gallagher Controller 6000 firmware to version 8.60.231116a or later.
CVE-2023-24590 affects Gallagher Controller 6000 firmware versions up to and including 8.50 and those in the range of 8.60 but prior to 8.60.231116a.
CVE-2023-24590 can lead to remote memory read/write operations and cause crashes, resulting in a denial of service for the Gallagher Controller 6000.
CVE-2023-24590 is a format string vulnerability found in the optional diagnostic web interface of the Gallagher Controller 6000.