CVE-2024-41146 is a Denial-of-Service vulnerability (CWE-694) affecting Controller 6000 and Controller 7000 platforms, specifically firmware versions 9.10, 9.00, 8.90, and all prior 8.80 versions. An attacker with physical access to HBUS communication cabling can exploit this flaw, requiring a device reboot to restore functionality. Rated Medium severity (CVSS 4.6), it has a physical attack vector with low complexity and no user interaction. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Gallagher | Controller 6000 And Controller 7000 | >= 8.90, < vCR8.90.241107a, >= 9.00, < vCR9.00.241108a, >= 9.10, < vCR9.10.241108a, >= 0, <= 8.80CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.