CVE-2023-6355

Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. 

This issue affects: Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507 (MR1)), 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)).

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gallaghercontroller_7000_firmware
8.70 ≤
𝑥
< 8.70.231204a
gallaghercontroller_7000_firmware
8.80 ≤
𝑥
< 8.80.231204a
gallaghercontroller_7000_firmware
8.90 ≤
𝑥
< 8.90.231204a
gallaghercontroller_7000_firmware
9.00 ≤
𝑥
< 9.00.231204b
𝑥
= Vulnerable software versions