CVE-2021-23230

Severity: Critical - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Components affected: Command Centre Server
Version of Command Centre affected: 8.40 prior to 8.40.1888 (MR3), 8.30 prior to 8.30.1359 (MR3), 8.20 prior to 8.20.1259 (MR5), 8.10 prior to 8.10.1284 (MR7), 8.00 and earlier. 
Reported by: Gallagher
Active exploitation of vulnerability*: No
Description of vulnerability:  A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 prior to 8.30.1359 (MR3); 8.20 prior to 8.20.1259 (MR5); 8.10 prior to 8.10.1284 (MR7); version 8.00 and prior versions.
Mitigation: Requires an operator account. If workstation restrictions are enabled would also require a valid workstation certificate.

Maintenance releases are now available for:

  • v8.40 - v8.40.1888(MR3)
  • v8.30 - v8.30.1359(MR3)
  • v8.20 - v8.20.1259(MR5)
  • v8.10 - v8.10.1284(MR7)

Important notes:

  • These maintenance upgrades require the Command Centre server to be upgraded.

 

*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication.

Stay up to date with Gallagher

Get the latest Gallagher news, updates, and event information delivered straight to your inbox.