First published: Tue Mar 05 2024(Updated: )
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <vEL9.00.1774 | |
Gallagher Command Centre | <vEL8.90.1751 | |
Gallagher Command Centre | <vEL8.80.1526 | |
Gallagher Command Centre | <vEL8.70.2526 | |
Gallagher Command Centre | <8.60 | |
Gallagher Command Centre | < | |
Gallagher Command Centre | <=8.60 | |
Gallagher Command Centre | >=8.70<8.70.2526 | |
Gallagher Command Centre | >=8.80<8.80.1526 | |
Gallagher Command Centre | >=8.90<8.90.1751 | |
Gallagher Command Centre | >=9.00<9.00.1774 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21815 is classified as a medium severity vulnerability due to insufficient protection of credentials.
To fix CVE-2024-21815, upgrade your Gallagher Command Centre to version vEL9.00.1774 or higher.
CVE-2024-21815 affects users of Gallagher Command Centre versions prior to vEL9.00.1774, vEL8.90.1751, and vEL8.80.1526.
CVE-2024-21815 involves insufficiently protected credentials, leading to access by unauthenticated users.
Yes, CVE-2024-21815 can potentially be exploited remotely by authenticated but unprivileged users.