← Back

CVE-2024-43690

nvd nist
Published: Sep 11, 2024Modified: Jun 17, 2026Deferred

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 6.0
Source: disclosures@gallagher.com (Secondary)

Description

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior.

Timeline

No history available yet.