CVE-2024-43107

Severity: High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

Components affected: Gallagher Milestone Integration Plugin

Version of MIPS Plugin affected: v4.0 prior to v4.0.32, all versions of v3.0 and prior.

Reported by: Gallagher Internal

Active exploitation of vulnerability*: No

Description of vulnerability:

Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g., alarm events) to be sent to the Plugin.

Mitigating factor: Impact of this vulnerability is limited to sites making use of the Gallagher Milestone Integration Plugin prior to v4.0.32.

*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication.

Our head office will be closed from December 19th to January 5th 2026 for the holiday period. We will respond to all contact forms upon return. For technical support, please contact your local team via the support number.

Stay up to date with Gallagher

Get the latest Gallagher news, updates, and event information delivered straight to your inbox.