Gallagher Command Centre Server
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*
- < vEL9.30.2482 (MR2)
- < vEL9.20.2819 (MR4)
- < vEL9.10.3672 (MR7)
- ~9.00
A vulnerability in Gallagher Command Centre Server exists in versions 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), and all versions of 9.00 and prior. This issue involves client-side enforcement of server-side security, allowing privileged operators to input invalid competency data that bypasses expiry checks. Only sites utilizing competency expiries for access control are affected.
Exploitation of this vulnerability could lead to unauthorized access or privileges by allowing the entry of invalid competency data that bypasses established expiry checks, potentially disrupting access control decisions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.