Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cg32-2535-p88w

Опубликовано: 05 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users.

This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users.

This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

EPSS

Процентиль: 27%
0.00098
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.1
nvd
почти 2 года назад

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

EPSS

Процентиль: 27%
0.00098
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-522