CVE Vulnerabilities

CVE-2023-23576

Incorrect Behavior Order

Published: Dec 18, 2023 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when competencies are used in the access decision.

This issue affects: Gallagher Command Centre: 8.90 prior to vEL8.90.1620 (MR2), 8.80 prior to vEL8.80.1369 (MR3), 8.70 prior to vEL8.70.2375 (MR5), 8.60 prior to vEL8.60.2550 (MR7), all versions of 8.50 and prior.

Weakness

The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways which may produce resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Command_centre Gallagher * 8.50 (including)
Command_centre Gallagher 8.60 (including) 8.60.2550 (excluding)
Command_centre Gallagher 8.70 (including) 8.70.2375 (excluding)
Command_centre Gallagher 8.80 (including) 8.80.1369 (excluding)
Command_centre Gallagher 8.90 (including) 8.90.1620 (excluding)

References