A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols.
This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50874 | A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)). |
Tue, 01 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2024-10-01T15:59:10.520Z
Reserved: 2023-11-01T22:24:52.286Z
Link: CVE-2023-46686
Updated: 2024-08-02T20:53:20.883Z
Status : Modified
Published: 2023-12-18T22:15:08.967
Modified: 2024-11-21T08:29:04.360
Link: CVE-2023-46686
No data.
OpenCVE Enrichment
No data.
EUVD