Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface.
This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.
References
Link | Resource |
---|---|
https://security.gallagher.com/Security-Advisories/CVE-2023-22439 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Gallagher
Published: 2023-12-18T21:58:41.026Z
Updated: 2023-12-18T21:58:41.026Z
Reserved: 2023-02-03T20:38:05.234Z
Link: CVE-2023-22439
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-12-18T22:15:07.807
Modified: 2023-12-28T18:50:15.597
Link: CVE-2023-22439
JSON object: View
Redhat Information
No data.
CWE