CVE-2019-19802 describes an improper authorization vulnerability in Gallagher Command Centre Server versions prior to v8.10.1134(MR4), v8.00.1161(MR5), v7.90.991(MR5), v7.80.960(MR2), and v7.70 or earlier. An authenticated user connecting via OPCUA can access all data typically replicated in a multi-server environment, bypassing intended privilege checks. This medium-severity vulnerability (CVSS 6.5) allows for high confidentiality impact without requiring user interaction, though it necessitates prior authentication. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.70CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
>= 7.80, < 7.80.960CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
>= 7.90, < 7.90.991CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
>= 8.00, < 8.00.1161CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* | ||
>= 8.10, < 8.10.1134CPE matchmatch criteria | cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.