CVE-2024-21815

EUVD-2024-19427
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. 

This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
GallagherCNA
9.1 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
gallaghercommand_centre
𝑥
≤ 8.60
gallaghercommand_centre
8.70 ≤
𝑥
< 8.70.2526
gallaghercommand_centre
8.80 ≤
𝑥
< 8.80.1526
gallaghercommand_centre
8.90 ≤
𝑥
< 8.90.1751
gallaghercommand_centre
9.00 ≤
𝑥
< 9.00.1774
𝑥
= Vulnerable software versions