CVE Published: 18/12/2023 |
CVE Updated: 01/10/2024 |
CVE Year: 2023 Source: Gallagher |
Vendor: Gallagher |
Product: Command Centre Diagnostics Service Status : PUBLISHED
CVE-2023-46686 Description
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols.
This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N