CVE-2023-22428: Gallagher Command Centre

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831(MR8), vEL8.40 and prior.

Affected products

  • Gallagher Command Centre: up to and including 8.40.2216; from 8.50, before 8.50.2831 (fixed in 8.50.2831); from 8.60, before 8.60.2347 (fixed in 8.60.2347); from 8.70, before 8.70.2185 (fixed in 8.70.2185); from 8.80, before 8.80.1192 (fixed in 8.80.1192)

Published 2023-07-24. Last modified 2026-06-17.