« Volver al listado

CVE-2026-20757

Estado: AnalizadaBaja (2.5)—

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.

This issue affects Command Centre Server:

9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-20757",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-20757",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-03T15:38:55.859473Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosures@gallagher.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.5,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "disclosures@gallagher.com",
      "affectedData": [
        {
          "vendor": "Gallagher",
          "product": "Command Centre Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "9.00"
            },
            {
              "status": "affected",
              "version": "9.40",
              "lessThan": "9.40.1976(MR1)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.30",
              "lessThan": "9.30.3382 (MR4)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.20",
              "lessThan": "9.20.3783 (MR6)",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.10",
              "lessThan": "9.10.4647 (MR9)",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-03-03T03:15:54.377",
  "references": [
    {
      "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20757",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosures@gallagher.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosures@gallagher.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-667"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server.\n\n\n\nThis issue affects Command Centre Server: \n\n9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de bloqueo indebido (CWE-667) en la integración de Gallagher Morpho permite a un operador privilegiado causar una denegación de servicio limitada en el servidor de Command Centre.\n\nEste problema afecta al servidor de Command Centre:\n9.40 anterior a vEL9.40.1976(MR1), 9.30 anterior a vEL9.30.3382 (MR4), 9.20 anterior a vEL9.20.3783 (MR6), 9.10 anterior a vEL9.10.4647 (MR9), todas las versiones de 9.00 y anteriores."
    }
  ],
  "lastModified": "2026-08-18T15:54:36.190",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A4C2E06-7573-425D-B10D-F7ACD09A7D67",
              "versionEndExcluding": "9.10.4647"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "756E179B-2EF0-409A-80AF-98EC7F1F23E4",
              "versionEndExcluding": "9.20.3783",
              "versionStartIncluding": "9.20.1043"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B5EEDA8-AB72-49E4-99F0-F3A29712ECC9",
              "versionEndExcluding": "9.30.3382",
              "versionStartIncluding": "9.30.1594"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01AAA308-886D-4E29-9D90-C1ACAC04C260",
              "versionEndExcluding": "9.40.1976",
              "versionStartIncluding": "9.40.1359"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosures@gallagher.com"
}