← Back

CVE-2021-23230

nvd nist
Published: Jun 11, 2021Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions.

Affected (9)

1 product
Command Centre
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Gallagher
Up to 8.00
From 8.10 to 8.10.1284
From 8.20 to 8.20.1259
From 8.30 to 8.30.1359
From 8.40 to 8.40.1888
Version 8.10.1284
Version 8.20.1259
Version 8.30.1359
Version 8.40.1888

References (2)

Source: disclosures@gallagher.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.