diff --git a/advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json b/advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json new file mode 100644 index 00000000000..ff7398ce48d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcg6-gqfh-q5rq", + "modified": "2025-03-10T03:30:51Z", + "published": "2025-03-10T03:30:51Z", + "aliases": [ + "CVE-2024-41724" + ], + "details": "Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. \n\n\n\n\nThis issue affects all versions of Gallagher Command Centre prior to 9.20.1043.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41724" + }, + { + "type": "WEB", + "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-41724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T03:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json b/advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json new file mode 100644 index 00000000000..d97502e5301 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r25q-23cf-rhp4", + "modified": "2025-03-10T03:30:51Z", + "published": "2025-03-10T03:30:51Z", + "aliases": [ + "CVE-2024-43107" + ], + "details": "Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin.\nThis issue effects Gallagher MIPS Plugin v4.0 prior to v4.0.32, all versions of v3.0 and prior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43107" + }, + { + "type": "WEB", + "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-43107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T03:15:26Z" + } +} \ No newline at end of file