PT-2024-19378 · Gallagher · Gallagher Controller 7000
Published
2024-03-04
·
Updated
2024-03-05
·
CVE-2024-22383
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Gallagher Controller 7000 versions 8.70 prior to vCR8.70.240209a
Gallagher Controller 7000 versions 8.80 prior to vCR8.80.240209a
Gallagher Controller 7000 versions 8.90 prior to vCR8.90.240209b
Gallagher Controller 7000 versions 9.00 prior to vCR9.00.231204b
Description
The issue is related to a missing release of resource after effective lifetime, resulting in HBUS connected T-Series readers not automatically recovering after coming under attack over the RS-485 interface. This leads to a persistent denial of service.
Recommendations
For Gallagher Controller 7000 version 8.70 prior to vCR8.70.240209a, update to vCR8.70.240209a or later.
For Gallagher Controller 7000 version 8.80 prior to vCR8.80.240209a, update to vCR8.80.240209a or later.
For Gallagher Controller 7000 version 8.90 prior to vCR8.90.240209b, update to vCR8.90.240209b or later.
For Gallagher Controller 7000 version 9.00 prior to vCR9.00.231204b, update to vCR9.00.231204b or later.
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gallagher Controller 7000