Page 3 of 11 results (0.003 seconds)

CVSS: 9.9EPSS: 0%CPEs: 9EXPL: 0

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); 8.10 versions prior to 8.10.1284 (MR7); version 8.00 and prior versions. Una vulnerabilidad de Inyección SQL en la interfaz OPCUA de Gallagher Command Centre, permite a un operador remoto no privilegiado de Command Centre modificar las bases de datos de Command Centre sin ser detectado. Este problema afecta a: Gallagher Command Centre versiones 8.40 anteriores a 8.40.1888 (MR3); versiones 8.30 anteriores a 8.30.1359 (MR3); versiones 8.20 anteriores a 8.20.1259 (MR5); versiones 8.10 anteriores a 8.10.1284 (MR7); versiones 8.00 y anteriores • https://security.gallagher.com/Security-Advisories/CVE-2021-23230 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •