Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug.
This issue affects: Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507 (MR1)), 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)).
References
| Link | Resource |
|---|---|
| https://security.gallagher.com/Security-Advisories/CVE-2023-6355 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
02 Jan 2024, 15:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Gallagher controller 7000
Gallagher Gallagher controller 7000 Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
| CWE | CWE-863 | |
| CPE | cpe:2.3:o:gallagher:controller_7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:gallagher:controller_7000:-:*:*:*:*:*:*:* |
|
| References | () https://security.gallagher.com/Security-Advisories/CVE-2023-6355 - Vendor Advisory |
18 Dec 2023, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-12-18 22:15
Updated : 2024-01-02 15:26
NVD link : CVE-2023-6355
Mitre link : CVE-2023-6355
JSON object : View
Products Affected
gallagher
- controller_7000
- controller_7000_firmware
CWE
CWE-863
Incorrect Authorization
