SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-23193

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server.

MEDIUM 6.5EPSS 0.70%

Does this matter?

Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.

Description

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ; 8.40 versions prior to 8.40.2063 (MR4); 8.30 versions prior to 8.30.1454 (MR4) ; 8.20 versions prior to 8.20.1291 (MR6); version 8.10 and prior versions.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.70% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-269
Affected
gallagher/command centre
Source
disclosures@gallagher.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.