Gallagher Milestone Integration Plugin Improper Certificate Validation Vulnerability

Vulnerability

A vulnerability exists in the Gallagher Milestone Integration Plugin (MIP) versions 4.0 prior to 4.0.32, as well as all versions of 3.0 and prior. The issue stems from improper certificate validation, allowing unauthenticated messages, such as alarm events, to be sent to the plugin.

Impact

Exploitation of this vulnerability could lead to the injection of unauthenticated messages into the Gallagher Milestone Integration Plugin, potentially allowing for the manipulation or spoofing of alarm events.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.