PT-2019-12821 · Gallagher · Gallagher Command Centre

Published

2019-06-06

·

Updated

2021-07-21

·

CVE-2019-12492

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gallagher Command Centre versions prior to 8.00.1128 Gallagher Command Centre versions 7.90.x prior to 7.90.961 Gallagher Command Centre versions prior to 7.80.939
Description The issue allows for arbitrary event creation and information disclosure. This is possible via the FT Command Centre Service and FT Controller Service services.
Recommendations For versions prior to 7.80.939, update to version 7.80.939 or later. For versions 7.90.x prior to 7.90.961, update to version 7.90.961 or later. For versions prior to 8.00.1128, update to version 8.00.1128 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12492

Affected Products

Gallagher Command Centre