Gallagher Command Centre Server是新西兰Gallagher公司的一个用于对建筑物内基础设施进行监控、管理的管理系统。 Gallagher Command Centre OPCUA接口 存在SQL注入漏洞,该漏洞源于基于数据库的应用缺少对外部输入SQL语句的验证。攻击者可利用该漏洞允许远程非特权指挥中心操作员在未被发现的情况下修改指挥中心数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gallagher | Command Centre | unspecified ~ 8.00 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23140 | 9.9 CRITICAL | Gallagher Command Centre Server 安全漏洞 |
| CVE-2021-23204 | 8.1 HIGH | Gallagher Command Centre Server 安全漏洞 |
| CVE-2021-23205 | 8.1 HIGH | Gallagher Command Centre Server 处理逻辑错误漏洞 |
| CVE-2021-23136 | 6.5 MEDIUM | Gallagher Command Centre Server 安全漏洞 |
| CVE-2021-23182 | 6.0 MEDIUM | Gallagher Command Centre Server 加密问题漏洞 |
| CVE-2021-23211 | 6.0 MEDIUM | Gallagher Command Centre Server 安全漏洞 |
No comments yet