Vulnerability Details CVE-2021-23230
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.0%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 3.5
Products affected by CVE-2021-23230
-
cpe:2.3:a:gallagher:command_centre:*
-
cpe:2.3:a:gallagher:command_centre:-
-
cpe:2.3:a:gallagher:command_centre:7.70
-
cpe:2.3:a:gallagher:command_centre:7.80
-
cpe:2.3:a:gallagher:command_centre:7.80.939
-
cpe:2.3:a:gallagher:command_centre:7.80.960
-
cpe:2.3:a:gallagher:command_centre:7.90
-
cpe:2.3:a:gallagher:command_centre:7.90.0
-
cpe:2.3:a:gallagher:command_centre:7.90.1038
-
cpe:2.3:a:gallagher:command_centre:7.90.961
-
cpe:2.3:a:gallagher:command_centre:7.90.991
-
cpe:2.3:a:gallagher:command_centre:8.0
-
cpe:2.3:a:gallagher:command_centre:8.00
-
cpe:2.3:a:gallagher:command_centre:8.10
-
cpe:2.3:a:gallagher:command_centre:8.10.1092
-
cpe:2.3:a:gallagher:command_centre:8.10.1134
-
cpe:2.3:a:gallagher:command_centre:8.10.1211
-
cpe:2.3:a:gallagher:command_centre:8.10.1253
-
cpe:2.3:a:gallagher:command_centre:8.10.1284
-
cpe:2.3:a:gallagher:command_centre:8.20
-
cpe:2.3:a:gallagher:command_centre:8.20.1093
-
cpe:2.3:a:gallagher:command_centre:8.20.1166
-
cpe:2.3:a:gallagher:command_centre:8.20.1218
-
cpe:2.3:a:gallagher:command_centre:8.20.1259
-
cpe:2.3:a:gallagher:command_centre:8.30
-
cpe:2.3:a:gallagher:command_centre:8.30.1236
-
cpe:2.3:a:gallagher:command_centre:8.30.1299
-
cpe:2.3:a:gallagher:command_centre:8.30.1359
-
cpe:2.3:a:gallagher:command_centre:8.40.1888