PT-2023-32624 · Gallagher · Gallagher Controller 7000

Published

2023-12-18

·

Updated

2024-01-02

·

CVE-2023-6355

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gallagher Controller 7000 versions 8.70 prior to vCR8.70.231204a Gallagher Controller 7000 versions 8.80 prior to vCR8.80.231204a Gallagher Controller 7000 versions 8.90 prior to vCR8.90.231204a Gallagher Controller 7000 versions 9.00 prior to vCR9.00.231204b
Description The issue is related to the incorrect selection of fuse values in the Controller 7000 platform, which allows an attacker to bypass some protection mechanisms and enable local debug.
Recommendations For version 8.70, update to vCR8.70.231204a or later. For version 8.80, update to vCR8.80.231204a or later. For version 8.90, update to vCR8.90.231204a or later. For version 9.00, update to vCR9.00.231204b or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6355

Affected Products

Gallagher Controller 7000