CVE-2022-26078

Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 6000 vCR8.60 versions prior to 220303a; vCR8.50 versions prior to 220303a; vCR8.40 versions prior to 220303a; vCR8.30 versions prior to 220303a.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
GallagherCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
gallaghercontroller_6000_firmware
8.30 ≤
𝑥
< 8.30.220303a
gallaghercontroller_6000_firmware
8.40 ≤
𝑥
< 8.40.220303a
gallaghercontroller_6000_firmware
8.50 ≤
𝑥
< 8.50.220303a
gallaghercontroller_6000_firmware
8.60 ≤
𝑥
< 8.60.220303a
𝑥
= Vulnerable software versions