CVE-2024-43107
Severity: High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Components affected: Gallagher Milestone Integration Plugin
Version of MIPS Plugin affected: v4.0 prior to v4.0.32, all versions of v3.0 and prior.
Reported by: Gallagher Internal
Active exploitation of vulnerability*: No
Description of vulnerability:
Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g., alarm events) to be sent to the Plugin.
Mitigating factor: Impact of this vulnerability is limited to sites making use of the Gallagher Milestone Integration Plugin prior to v4.0.32.
*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication.
Stay up to date with Gallagher
Get the latest Gallagher news, updates, and event information delivered straight to your inbox.