« Volver al listado

CVE-2023-22439

Estado: ModificadaMedia (4.3)—

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface.

This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-22439",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosures@gallagher.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "disclosures@gallagher.com",
      "affectedData": [
        {
          "vendor": "Gallagher",
          "product": "Controller 6000/ Controller 7000",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "8.50"
            },
            {
              "status": "affected",
              "version": "8.90",
              "lessThan": "vCR8.90.231204a",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.80",
              "lessThan": "vCR8.80.231204a",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.70",
              "lessThan": "vCR8.70.231204a",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "8.60",
              "lessThan": "vCR8.60.231116a",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-18T22:15:07.807",
  "references": [
    {
      "url": "https://security.gallagher.com/Security-Advisories/CVE-2023-22439",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosures@gallagher.com"
    },
    {
      "url": "https://security.gallagher.com/Security-Advisories/CVE-2023-22439",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosures@gallagher.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nImproper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface.\n\nThis issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.\n\n"
    },
    {
      "lang": "es",
      "value": "Se puede utilizar una validación de entrada incorrecta de una solicitud HTTP grande en la interfaz web de diagnóstico opcional de Controller 6000 y Controller 7000 (puerto 80) para realizar una denegación de servicio de la interfaz web de diagnóstico. Este problema afecta a: \nGallagher Controller 6000 y 7000 8.90 antes de vCR8.90.231204a (distribuido en 8.90.1620 (MR2)), \n8.80 antes de vCR8.80.231204a (distribuido en 8.80.1369 (MR3)), \n8.70 antes de vCR8. 70.231204a (distribuido en 8.70.2375 (MR5)), \n8.60 antes de vCR8.60.231116a (distribuido en 8.60.2550 (MR7)), \ntodas las versiones de 8.50 y anteriores."
    }
  ],
  "lastModified": "2026-06-17T05:35:26.867",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3183049E-D5F5-416E-B5B6-140B02510BC0",
              "versionEndIncluding": "8.50"
            },
            {
              "criteria": "cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "162DF4B0-4F15-48D0-9D67-2AD509FD1FAD",
              "versionEndExcluding": "8.60.231116a",
              "versionStartIncluding": "8.60"
            },
            {
              "criteria": "cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30EEB0FF-D2F2-47DA-9666-6532730B195F",
              "versionEndExcluding": "8.70.231204a",
              "versionStartIncluding": "8.70"
            },
            {
              "criteria": "cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D11F6F34-20E1-4BF8-BA36-819F2B153320",
              "versionEndExcluding": "8.80.231204a",
              "versionStartIncluding": "8.80"
            },
            {
              "criteria": "cpe:2.3:o:gallagher:controller_6000_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "715CA029-60DF-422B-90BA-C806DCE041FC",
              "versionEndExcluding": "8.90.231204a",
              "versionStartIncluding": "8.90"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gallagher:controller_6000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5AF2B03B-B033-439F-8CEE-334FA8053278"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23C4F969-A44F-40D6-A92B-56A2653A0786",
              "versionEndIncluding": "8.50"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "189BCB50-4E9F-4E0B-B03F-D703BD14B6C9",
              "versionEndExcluding": "8.60.231116a",
              "versionStartIncluding": "8.60"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63286868-84A7-492C-8F48-E0FB883C5666",
              "versionEndExcluding": "8.70.231204a",
              "versionStartIncluding": "8.70"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48DE400E-2C3D-485C-8C8E-DA79BC155E7F",
              "versionEndExcluding": "8.80.231204a",
              "versionStartIncluding": "8.80"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14A61AE2-E3D1-4BEE-B5E1-361E6E0A617E",
              "versionEndExcluding": "8.90.231204a",
              "versionStartIncluding": "8.90"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gallagher:controller_6000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5AF2B03B-B033-439F-8CEE-334FA8053278"
            },
            {
              "criteria": "cpe:2.3:h:gallagher:controller_7000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D0F7F6A6-8F69-45C1-A59D-D9FB3FD0C1C7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "disclosures@gallagher.com"
}