Gallagher Command Centre Server Privilege Context Switching Error Vulnerability

Vulnerability

A Privilege Context Switching Error (CWE-270) has been identified in Gallagher Command Centre Server. This vulnerability could allow a privileged Operator with high-level access in one Division to perform limited privileged activities across Division boundaries. The issue affects Command Centre Server versions 9.30 prior to 9.30.1874 (MR1), 9.20 prior to 9.20.2337 (MR3), 9.10 prior to 9.10.3194 (MR6), 9.00 prior to 9.00.3371 (MR7), and all versions of 8.90 and prior.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing Operators to perform restricted activities in other Divisions.

Added: Jul 10, 2025, 3:18 AM
Updated: Jul 10, 2025, 3:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.6
exploitability
3.0
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.