Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior.
History

Wed, 11 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Gallagher
Gallagher command Centre
CPEs cpe:2.3:a:gallagher:command_centre:-:*:*:*:*:*:*:*
Vendors & Products Gallagher
Gallagher command Centre
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 04:30:00 +0000

Type Values Removed Values Added
Description Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior.
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gallagher

Published: 2024-09-11T04:04:19.129Z

Updated: 2024-09-11T18:34:36.166Z

Reserved: 2024-08-28T02:46:11.119Z

Link: CVE-2024-43690

cve-icon Vulnrichment

Updated: 2024-09-11T18:34:31.385Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-11T05:15:02.843

Modified: 2024-09-11T16:26:11.920

Link: CVE-2024-43690

cve-icon Redhat

No data.