Impact
An Incorrect Privilege Assignment flaw implemented in the Gallagher Command Centre Server allows an authenticated operator with limited privilege to carry out operations they should not be permitted to perform. The weakness, classified as CWE-266, directly impacts the integrity of the system by enabling the elevation of privileges within the server’s operational scope.
Affected Systems
Gallagher Command Centre Server versions 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), and all 9.10 releases are affected. Patched releases are available starting with the specified milestones for each major version.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate authenticated user with limited privileges; from that position an attacker can perform privileged actions beyond their authorized scope within the server’s environment.
OpenCVE Enrichment