Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-43690", "assignerOrgId": "0c426f27-3ee1-4eff-be88-288d5a1822bc", "state": "PUBLISHED", "assignerShortName": "Gallagher", "dateReserved": "2024-08-28T02:46:11.119Z", "datePublished": "2024-09-11T04:04:19.129Z", "dateUpdated": "2024-09-11T18:34:36.166Z"}, "containers": {"cna": {"affected": [{"defaultStatus": "affected", "product": "Command Centre Server", "vendor": "Gallagher", "versions": [{"lessThanOrEqual": "8.70", "status": "affected", "version": "0", "versionType": "custom"}, {"lessThan": "vEL9.10.1530(MR2)", "status": "affected", "version": "9.10", "versionType": "custom"}, {"lessThan": "vEL9.00.2168 (MR4)", "status": "affected", "version": "9.00", "versionType": "custom"}, {"lessThan": "vEL8.90.2155 (MR5)", "status": "affected", "version": "8.90", "versionType": "custom"}, {"lessThan": "vEL8.80.1938 (MR6)", "status": "affected", "version": "8.80", "versionType": "custom"}]}], "descriptions": [{"lang": "en", "supportingMedia": [{"base64": false, "type": "text/html", "value": "<span style=\"background-color: rgb(255, 255, 255);\">Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE).</span>\n\n<p><b>This issue affects:</b> Command Centre Server and Command Centre Workstations <span style=\"background-color: rgb(255, 255, 255);\">9.10 prior to </span><span style=\"background-color: rgb(255, 255, 255);\">vEL9.10.1530 (MR2), </span><span style=\"background-color: rgb(255, 255, 255);\">9.00 prior to </span><span style=\"background-color: rgb(255, 255, 255);\">vEL9.00.2168 (MR4), </span><span style=\"background-color: rgb(255, 255, 255);\">8.90 prior to vEL8.90.2155 (MR5), </span><span style=\"background-color: rgb(255, 255, 255);\">8.80 prior to vEL8.80.1938 (MR6), </span><span style=\"background-color: rgb(255, 255, 255);\">all versions of 8.70 and prior.</span>\n\n</p>"}], "value": "Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE).\n\nThis issue affects: Command Centre Server and Command Centre Workstations\u00a09.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior."}], "metrics": [{"cvssV3_1": {"attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "HIGH", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H", "version": "3.1"}, "format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "problemTypes": [{"descriptions": [{"cweId": "CWE-829", "description": "CWE-829 Inclusion of Functionality from Untrusted Control Sphere", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"orgId": "0c426f27-3ee1-4eff-be88-288d5a1822bc", "shortName": "Gallagher", "dateUpdated": "2024-09-11T04:04:19.129Z"}, "references": [{"url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-43690"}], "source": {"discovery": "INTERNAL"}, "x_generator": {"engine": "Vulnogram 0.2.0"}}, "adp": [{"affected": [{"vendor": "gallagher", "product": "command_centre", "cpes": ["cpe:2.3:a:gallagher:command_centre:-:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "0", "status": "affected", "lessThanOrEqual": "8.70", "versionType": "custom"}, {"version": "9.10", "status": "affected", "lessThanOrEqual": "9.10.1530(mr2)", "versionType": "custom"}, {"version": "9.00", "status": "affected", "lessThanOrEqual": "9.00.2168(mr4)", "versionType": "custom"}, {"version": "8.90", "status": "affected", "lessThanOrEqual": "8.90.2155(mr5)", "versionType": "custom"}, {"version": "8.80", "status": "affected", "lessThanOrEqual": "8.80.1938(mr6)", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-09-11T18:20:31.031982Z", "id": "CVE-2024-43690", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-11T18:34:36.166Z"}}]}}