Impact
An Incorrect Privilege Assignment (CWE-266) vulnerability in Gallagher Command Centre Server permits an authenticated operator with limited privileges to perform operations beyond their normal authorization scope, potentially compromising the integrity of the system.
Affected Systems
Gallagher Command Centre Server is affected in all releases up to version 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), and all 9.10 releases; newer releases contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate authenticated account with limited privileges; from that position an attacker can elevate privileges within the server’s operational scope accounts.
OpenCVE Enrichment