CVE-2024-21815

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. 

This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
GallagherCNA
9.1 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
gallaghercommand_centre
𝑥
≤ 8.60
gallaghercommand_centre
8.70 ≤
𝑥
< 8.70.2526
gallaghercommand_centre
8.80 ≤
𝑥
< 8.80.1526
gallaghercommand_centre
8.90 ≤
𝑥
< 8.90.1751
gallaghercommand_centre
9.00 ≤
𝑥
< 9.00.1774
𝑥
= Vulnerable software versions