Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature.
This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28599 | Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, before vCR8.70.230201a, before vCR8.60.230201b, before vCR8.50.230201a, all versions of vCR8.40 and prior. |
Solution
No solution given by the vendor.
Workaround
Ensure dipswitch 1 is turned off on all Controllers and the option, "Dipswitch 1 controls the diagnostic web interface", is not checked in Configuration Client on Controller property pages. Do not use the Controller override, "Enable WWW Connections". Refer to the Gallagher Command Centre Hardening Guide for more details.
Fri, 10 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Gallagher
Published:
Updated: 2025-01-10T18:47:07.773Z
Reserved: 2023-02-03T20:38:05.230Z
Link: CVE-2023-24584
Updated: 2024-08-02T11:03:18.735Z
Status : Modified
Published: 2023-06-01T05:15:09.767
Modified: 2024-11-21T07:48:10.787
Link: CVE-2023-24584
No data.
OpenCVE Enrichment
No data.
EUVD