First published: Tue Mar 05 2024(Updated: )
Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface, resulting in a persistent denial of service. This issue affects: All variants of the Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507(MR1)), 8.90 prior to vCR8.90.240209b (distributed in 8.90.1751 (MR3)), 8.80 prior to vCR8.80.240209a (distributed in 8.80.1526 (MR4)), 8.70 prior to vCR8.70.240209a (distributed in 8.70.2526 (MR6)).
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Controller 7000 Firmware | <vCR9.00.231204b | |
Gallagher Controller 7000 Firmware | <vCR8.90.240209b | |
Gallagher Controller 7000 Firmware | <vCR8.80.240209a | |
Gallagher Controller 7000 Firmware | <vCR8.70.240209a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22383 has been identified with a significant severity due to its potential to cause persistent denial of service.
To mitigate CVE-2024-22383, it is recommended to upgrade the Gallagher Controller 7000 to the latest patched version above vCR9.00.231204b.
CVE-2024-22383 affects all variants of the Gallagher Controller 7000 up to versions vCR9.00.231204b, vCR8.90.240209b, vCR8.80.240209a, and vCR8.70.240209a.
CVE-2024-22383 prevents T-Series readers connected via HBUS from automatically recovering after an attack over the RS-485 interface.
There is no officially recommended workaround for CVE-2024-22383; users should focus on applying the necessary updates.