PT-2021-15392 · Gallagher · Gallagher Command Centre

Published

2021-11-18

·

Updated

2022-10-07

·

CVE-2021-23146

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gallagher Command Centre versions prior to 8.40.1888 (MR3) Gallagher Command Centre versions prior to 8.30.1454 (MR3) Gallagher Command Centre versions prior to 8.20.1291 (MR5) Gallagher Command Centre versions prior to 8.10.1284 (MR7) Gallagher Command Centre version 8.00 and prior versions
Description An Incomplete Comparison with Missing Factors issue in the Gallagher Controller allows an attacker to bypass PIV verification.
Recommendations For versions prior to 8.40.1888 (MR3), update to version 8.40.1888 (MR3) or later. For versions prior to 8.30.1454 (MR3), update to version 8.30.1454 (MR3) or later. For versions prior to 8.20.1291 (MR5), update to version 8.20.1291 (MR5) or later. For versions prior to 8.10.1284 (MR7), update to version 8.10.1284 (MR7) or later. For version 8.00 and prior versions, update to a version later than 8.00.

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-23146

Affected Products

Gallagher Command Centre