CVE-2021-23230
Published Jun 11, 2021
Last updated 3 years ago
Overview
- Description
- A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions.
- Source
- disclosures@gallagher.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:P/A:N
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63D6F225-FF42-4B2A-9CAE-0DF2366F28E3", "versionEndIncluding": "8.00" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "265809A9-AA8A-41E1-A3A7-E1CC6157D087", "versionEndExcluding": "8.10.1284", "versionStartIncluding": "8.10" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A95D4CF5-6A49-45A4-A145-D12ACCA0FF6C", "versionEndExcluding": "8.20.1259", "versionStartIncluding": "8.20" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB8A27CD-C93A-4ED5-AECE-39EB05788C5B", "versionEndExcluding": "8.30.1359", "versionStartIncluding": "8.30" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2157A0E-4B51-4D16-8A6E-0FC711C1961B", "versionEndExcluding": "8.40.1888", "versionStartIncluding": "8.40" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:8.10.1284:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8C88566-E97C-46A1-97A9-842B68B2B255" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:8.20.1259:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C951E03-F376-4D1B-92EB-29D8EDF3088C" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:8.30.1359:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C4D6597-1327-443C-9D8A-DADD1DCFB527" }, { "criteria": "cpe:2.3:a:gallagher:command_centre:8.40.1888:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BEAAFEE0-3595-47D2-9B84-7A56320C7FE6" } ], "operator": "OR" } ] } ]