CRITICAL🇵🇱 Wersja polska

CVE-2024-21815

CVSS 9.1v3.1pub. 2024-03-05upd. 2025-02-10

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

🤖 AI Analysis
How it works

The vulnerability results from insufficient protection of stored or transmitted authentication credentials (CWE-522) used in integrations with external DVR systems. A logged-in user without assigned administrative privileges can read these credentials through the Command Centre server. Access to this data is possible remotely over the network, without requiring elevated privileges on the attacker's side.

Impact

An attacker with any account in the system can obtain authentication credentials to DVR systems, which may enable unauthorized access to camera feeds and further actions within the physical security infrastructure. Potential consequences include breach of confidentiality, and to a limited extent also integrity and availability of resources.

Mitigation & patch

Gallagher Command Centre should be updated to the following versions: 9.00 vEL9.00.1774 (MR2) or later, 8.90 vEL8.90.1751 (MR3) or later, 8.80 vEL8.80.1526 (MR4) or later, 8.70 vEL8.70.2526 (MR6) or later. For version 8.60 and earlier — migration to a supported version with available patch is necessary.

Who is affected

Gallagher Command Centre in versions: 9.00 before vEL9.00.1774 (MR2), 8.90 before vEL8.90.1751 (MR3), 8.80 before vEL8.80.1526 (MR4), 8.70 before vEL8.70.2526 (MR6) and all versions 8.60 and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Gallagher Command Centre

    APP
    Gallagher
    ≤ 8.608.70 – 8.70.2526 (excl.)8.80 – 8.80.1526 (excl.)8.90 – 8.90.1751 (excl.)9.00 – 9.00.1774 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-23230CRITICAL9.9PL ✓same product

SQL Injection w interfejsie OPCUA Gallagher Command Centre

CVE-2021-23140CRITICAL9.9PL ✓same product

Nieprawidłowa autoryzacja w Gallagher Command Centre — modyfikacja makr

CVE-2020-16098CRITICAL9.8PL ✓same product

Gallagher Command Centre — nieuprawnione odczytanie danych kart dostępu

CVE-2020-16096CRITICAL9.9PL ✓same product

Gallagher Command Centre — nieautoryzowany dostęp do wrażliwych danych replikacji

CVE-2019-15294CRITICAL9.8PL ✓same product

Gallagher Command Centre: hasło logowane jawnym tekstem w pliku logu