« Volver al listado

CVE-2023-23568

Estado: ModificadaMedia (5.4)—

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields.

This issue affects Command Centre: vEL

8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2),

vEL8.70 prior to

vEL8.70.2185 (MR4),

vEL8.60 prior to

vEL8.60.2347 (MR6),

vEL8.50 prior to

vEL8.50.2831 (MR8), all versions

vEL8.40 and prior

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-23568",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23568",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-17T13:01:07.162966Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosures@gallagher.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "disclosures@gallagher.com",
      "affectedData": [
        {
          "vendor": "Gallagher",
          "product": "Command Centre",
          "versions": [
            {
              "status": "affected",
              "version": "vEL8.90",
              "lessThan": "1318",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "vEL8.80",
              "lessThan": "1192",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "vEL8.70",
              "lessThan": "2185",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "vEL8.60",
              "lessThan": "2347",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "vEL8.50",
              "lessThan": "2831",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "vEL8.40"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-07-25T02:15:09.317",
  "references": [
    {
      "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-23568",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosures@gallagher.com"
    },
    {
      "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2023-23568",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosures@gallagher.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-285"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nImproper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields.\n\nThis issue affects Command Centre: vEL\n\n8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), \n\nvEL8.70 prior to \n\nvEL8.70.2185 (MR4), \n\nvEL8.60 prior to \n\nvEL8.60.2347 (MR6), \n\nvEL8.50 prior to \n\nvEL8.50.2831 (MR8), all versions \n\nvEL8.40 and prior\n\n\n\n"
    }
  ],
  "lastModified": "2026-06-17T05:37:27.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E51DC51C-E4D6-4C8D-8235-10258F79A6C5",
              "versionEndIncluding": "8.40.2216"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B23146CE-CE9D-4850-8169-D0C168A3D037",
              "versionEndExcluding": "8.50.2831",
              "versionStartIncluding": "8.50"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12131674-A0E9-4A12-BA87-C9207DA8C34C",
              "versionEndExcluding": "8.60.2347",
              "versionStartIncluding": "8.60"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE1E36DB-F15E-449A-A672-4853D31CE064",
              "versionEndExcluding": "8.70.2185",
              "versionStartIncluding": "8.70"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92A438BA-DC52-4253-B5B6-4BE8CD7A1CCA",
              "versionEndExcluding": "8.80.1192",
              "versionStartIncluding": "8.80"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "110D9A0C-409D-4B1F-84B6-274B15D87CA3",
              "versionEndExcluding": "8.90.1318",
              "versionStartIncluding": "8.90"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosures@gallagher.com"
}