Impact
An uncaught exception (CWE-248) in the diagnostic web interface of Gallagher Controller 6000 and Controller 7000 allows an authenticated operator to send particular requests that cause the controller to restart. The restart activity interrupts the diagnostic functions for a brief period, resulting in a temporary denial of service. No data disclosure or privilege escalation is possible from this flaw; the impact is confined to service availability for authorized users.
Affected Systems
The issue targets Gallagher Controller 7000 and Controller 6000 diagnostic web interfaces running Command Centre firmware versions 9.50 prior to vCR9.50.260616a, 9.40 prior to vCR9.40.260616a, 9.30 prior to vCR9.30.260616a, 9.20 prior to vCR9.20.260616a, and all releases of 9.10 and earlier.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity, and the EPSS score of < 1 % reflects an extremely low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access with operator‑level privileges, making the attack vector internal. An attacker could trigger a restart repeatedly to induce availability disruption, but each reboot is transient and can be mitigated by redundancy. Overall, the risk to confidentiality, integrity, or persistent availability is limited to short‑term service interruption.
OpenCVE Enrichment