CVE-2021-23204

Severity: High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Components affected: Command Centre Server
Version of Command Centre affected: 8.40 prior to 8.40.1888 (MR3), 8.30 prior to 8.30.1359 (MR3).
Reported by: Gallagher
Active exploitation of vulnerability*: No
Description of vulnerability:  Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 prior to 8.30.1359 (MR3).
Mitigation: Sites not using OSDP readers are not impacted. Command Centre versions prior to 8.30 are not impacted.

Maintenance releases are now available for:

  • v8.40 - v8.40.1888(MR3)
  • v8.30 - v8.30.1359(MR3)

Important notes:

  • These maintenance upgrades require the Command Centre server to be upgraded.

 

*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication

X
Cookies help us improve your website experience.
By using our website, you agree to our use of cookies.
Confirm