Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
The vulnerability results from insufficient protection of stored or transmitted authentication credentials (CWE-522) used in integrations with external DVR systems. A logged-in user without assigned administrative privileges can read these credentials through the Command Centre server. Access to this data is possible remotely over the network, without requiring elevated privileges on the attacker's side.
An attacker with any account in the system can obtain authentication credentials to DVR systems, which may enable unauthorized access to camera feeds and further actions within the physical security infrastructure. Potential consequences include breach of confidentiality, and to a limited extent also integrity and availability of resources.
Gallagher Command Centre should be updated to the following versions: 9.00 vEL9.00.1774 (MR2) or later, 8.90 vEL8.90.1751 (MR3) or later, 8.80 vEL8.80.1526 (MR4) or later, 8.70 vEL8.70.2526 (MR6) or later. For version 8.60 and earlier — migration to a supported version with available patch is necessary.
Gallagher Command Centre in versions: 9.00 before vEL9.00.1774 (MR2), 8.90 before vEL8.90.1751 (MR3), 8.80 before vEL8.80.1526 (MR4), 8.70 before vEL8.70.2526 (MR6) and all versions 8.60 and earlier.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LGallagher Command Centre
APPGallagher≤ 8.608.70 – 8.70.2526 (excl.)8.80 – 8.80.1526 (excl.)8.90 – 8.90.1751 (excl.)9.00 – 9.00.1774 (excl.)
Related vulnerabilities
SQL Injection w interfejsie OPCUA Gallagher Command Centre
Nieprawidłowa autoryzacja w Gallagher Command Centre — modyfikacja makr
Gallagher Command Centre — nieuprawnione odczytanie danych kart dostępu
Gallagher Command Centre — nieautoryzowany dostęp do wrażliwych danych replikacji
Gallagher Command Centre: hasło logowane jawnym tekstem w pliku logu