CWE
772
Advisory Published
Updated

CVE-2024-22383

First published: Tue Mar 05 2024(Updated: )

Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface, resulting in a persistent denial of service. This issue affects: All variants of the Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507(MR1)), 8.90 prior to vCR8.90.240209b (distributed in 8.90.1751 (MR3)), 8.80 prior to vCR8.80.240209a (distributed in 8.80.1526 (MR4)), 8.70 prior to vCR8.70.240209a (distributed in 8.70.2526 (MR6)).

Credit: disclosures@gallagher.com

Affected SoftwareAffected VersionHow to fix
Gallagher Controller 7000 Firmware<vCR9.00.231204b
Gallagher Controller 7000 Firmware<vCR8.90.240209b
Gallagher Controller 7000 Firmware<vCR8.80.240209a
Gallagher Controller 7000 Firmware<vCR8.70.240209a

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-22383?

    CVE-2024-22383 has been identified with a significant severity due to its potential to cause persistent denial of service.

  • How do I fix CVE-2024-22383?

    To mitigate CVE-2024-22383, it is recommended to upgrade the Gallagher Controller 7000 to the latest patched version above vCR9.00.231204b.

  • What products are affected by CVE-2024-22383?

    CVE-2024-22383 affects all variants of the Gallagher Controller 7000 up to versions vCR9.00.231204b, vCR8.90.240209b, vCR8.80.240209a, and vCR8.70.240209a.

  • What is the impact of CVE-2024-22383 on T-Series readers?

    CVE-2024-22383 prevents T-Series readers connected via HBUS from automatically recovering after an attack over the RS-485 interface.

  • Is there a workaround for CVE-2024-22383?

    There is no officially recommended workaround for CVE-2024-22383; users should focus on applying the necessary updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203