CVE-2024-23317
External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code execution.
This issue affects: 9.10 prior to vCR9.10.240520a (distributed in 9.10.1268(MR1)), 9.00 prior to vCR9.00.240521a (distributed in 9.00.1990(MR3)), 8.90 prior to vCR8.90.240520a (distributed in 8.90.1947 (MR4)), 8.80 prior to vCR8.80.240520a (distributed in 8.80.1726 (MR5)), 8.70 prior to vCR8.70.240520a (distributed in 8.70.2824 (MR7)), all versions of 8.60 and prior.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
- Base score: 6.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.17%
- Percentile among all scored CVEs: 5
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-73
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-23317",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-23317",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-11T14:25:33.804644Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosures@gallagher.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.3,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.5,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "disclosures@gallagher.com",
"affectedData": [
{
"vendor": "Gallagher",
"product": "Controller 6000 and Controller 7000",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "8.60",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.10",
"versionType": "custom",
"lessThanOrEqual": "vCR9.10.240520a"
},
{
"status": "affected",
"version": "9.00",
"versionType": "custom",
"lessThanOrEqual": "vCR9.00.240521a"
},
{
"status": "affected",
"version": "8.90",
"versionType": "custom",
"lessThanOrEqual": "vCR8.90.240520a"
},
{
"status": "affected",
"version": "8.80",
"versionType": "custom",
"lessThanOrEqual": "vCR8.80.240520a"
},
{
"status": "affected",
"version": "8.70",
"versionType": "custom",
"lessThanOrEqual": "vCR8.70.240520a"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:gallagher:controller_6000_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_6000_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "8.60"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_6000_firmware:8.70:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_6000_firmware",
"versions": [
{
"status": "affected",
"version": "8.70",
"lessThan": "8.70.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_6000_firmware:8.80:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_6000_firmware",
"versions": [
{
"status": "affected",
"version": "8.80",
"lessThan": "8.80.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_6000_firmware:8.90:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_6000_firmware",
"versions": [
{
"status": "affected",
"version": "8.90",
"lessThan": "8.90.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_6000_firmware:9.00:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_6000_firmware",
"versions": [
{
"status": "affected",
"version": "9.00",
"lessThan": "9.00.240521a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_6000_firmware:9.10:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_6000_firmware",
"versions": [
{
"status": "affected",
"version": "9.10",
"lessThan": "9.10.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_7000_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_7000_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "8.60"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_7000_firmware:8.70:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_7000_firmware",
"versions": [
{
"status": "affected",
"version": "8.70",
"lessThan": "8.70.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_7000_firmware:8.80:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_7000_firmware",
"versions": [
{
"status": "affected",
"version": "8.80",
"lessThan": "8.80.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_7000_firmware:8.90:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_7000_firmware",
"versions": [
{
"status": "affected",
"version": "8.90",
"lessThan": "8.90.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_7000_firmware:9.00:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_7000_firmware",
"versions": [
{
"status": "affected",
"version": "9.00",
"lessThan": "9.00.240521a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:2.3:o:gallagher:controller_7000_firmware:9.10:*:*:*:*:*:*:*"
],
"vendor": "gallagher",
"product": "controller_7000_firmware",
"versions": [
{
"status": "affected",
"version": "9.10",
"lessThan": "9.10.240520a",
"versionType": "custom"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-07-11T03:15:03.130",
"references": [
{
"url": "https://security.gallagher.com/Security-Advisories/CVE-2024-23317",
"source": "disclosures@gallagher.com"
},
{
"url": "https://security.gallagher.com/Security-Advisories/CVE-2024-23317",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosures@gallagher.com",
"description": [
{
"lang": "en",
"value": "CWE-73"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code execution. \n\nThis issue affects: 9.10 prior to vCR9.10.240520a (distributed in 9.10.1268(MR1)), 9.00 prior to vCR9.00.240521a (distributed in 9.00.1990(MR3)), 8.90 prior to vCR8.90.240520a (distributed in 8.90.1947 (MR4)), 8.80 prior to vCR8.80.240520a (distributed in 8.80.1726 (MR5)), 8.70 prior to vCR8.70.240520a (distributed in 8.70.2824 (MR7)), all versions of 8.60 and prior."
},
{
"lang": "es",
"value": "El control externo del nombre o ruta del archivo (CWE-73) en el Controlador 6000 y el Controlador 7000 permite a un atacante con acceso local al Controlador realizar la ejecución de código arbitrario. Este problema afecta a: 9.10 anterior a vCR9.10.240520a (distribuido en 9.10.1268(MR1)), 9.00 anterior a vCR9.00.240521a (distribuido en 9.00.1990(MR3)), 8.90 anterior a vCR8.90.240520a (distribuido en 8.90.1947 (MR4)), 8.80 antes de vCR8.80.240520a (distribuido en 8.80.1726 (MR5)), 8.70 antes de vCR8.70.240520a (distribuido en 8.70.2824 (MR7)), todas las versiones de 8.60 y anteriores ."
}
],
"lastModified": "2026-06-17T07:12:34.973",
"sourceIdentifier": "disclosures@gallagher.com"
}