Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature.




This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-28599 Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior.
Fixes

Solution

No solution given by the vendor.


Workaround

Ensure dipswitch 1 is turned off on all Controllers and the option, "Dipswitch 1 controls the diagnostic web interface", is not checked in Configuration Client on Controller property pages. Do not use the Controller override, "Enable WWW Connections". Refer to the Gallagher Command Centre Hardening Guide for more details.

History

Fri, 10 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gallagher

Published:

Updated: 2025-01-10T18:47:07.773Z

Reserved: 2023-02-03T20:38:05.230Z

Link: CVE-2023-24584

cve-icon Vulnrichment

Updated: 2024-08-02T11:03:18.735Z

cve-icon NVD

Status : Modified

Published: 2023-06-01T05:15:09.767

Modified: 2024-11-21T07:48:10.787

Link: CVE-2023-24584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.