Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1299(MR2); 8.20 versions prior to 8.20.1218(MR4); 8.10 versions prior to 8.10.1253(MR6); 8.00 versions prior to 8.00.1252(MR7); version 7.90 and prior versions.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Command_centre | Gallagher | * | 7.90.0 (excluding) |
Command_centre | Gallagher | 8.00 (including) | 8.00.1252 (excluding) |
Command_centre | Gallagher | 8.10 (including) | 8.10.1253 (excluding) |
Command_centre | Gallagher | 8.20 (including) | 8.20.1218 (excluding) |
Command_centre | Gallagher | 8.30 (including) | 8.30.1299 (excluding) |
Command_centre | Gallagher | 8.00.1252 (including) | 8.00.1252 (including) |
Command_centre | Gallagher | 8.00.1252-maintenance_release7 (including) | 8.00.1252-maintenance_release7 (including) |
Command_centre | Gallagher | 8.10.1253 (including) | 8.10.1253 (including) |
Command_centre | Gallagher | 8.10.1253-maintenance_release6 (including) | 8.10.1253-maintenance_release6 (including) |
Command_centre | Gallagher | 8.20.1218 (including) | 8.20.1218 (including) |
Command_centre | Gallagher | 8.20.1218-maintenance_release4 (including) | 8.20.1218-maintenance_release4 (including) |
Command_centre | Gallagher | 8.30.1299 (including) | 8.30.1299 (including) |
Command_centre | Gallagher | 8.30.1299-maintenance_release2 (including) | 8.30.1299-maintenance_release2 (including) |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.