Severity: Critical - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Components affected: Command Centre Server
Version of Command Centre affected: 8.40 prior to 8.40.1888 (MR3), 8.30 prior to 8.30.1359 (MR3), 8.20 prior to 8.20.1259 (MR5), 8.10 prior to 8.10.1284 (MR7), 8.00 and earlier.
Reported by: Gallagher
Active exploitation of vulnerability*: No
Description of vulnerability: A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 prior to 8.30.1359 (MR3); 8.20 prior to 8.20.1259 (MR5); 8.10 prior to 8.10.1284 (MR7); version 8.00 and prior versions.
Mitigation: Requires an operator account. If workstation restrictions are enabled would also require a valid workstation certificate.
Maintenance releases are now available for:
- v8.40 - v8.40.1888(MR3)
- v8.30 - v8.30.1359(MR3)
- v8.20 - v8.20.1259(MR5)
- v8.10 - v8.10.1284(MR7)
- These maintenance upgrades require the Command Centre server to be upgraded.
*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication.