From b5d1505dde5aca35a8d581231b66c97b14e7be1f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 10 Mar 2025 03:32:41 +0000 Subject: [PATCH] Publish Advisories GHSA-jcg6-gqfh-q5rq GHSA-r25q-23cf-rhp4 --- .../GHSA-jcg6-gqfh-q5rq.json | 36 +++++++++++++++++++ .../GHSA-r25q-23cf-rhp4.json | 36 +++++++++++++++++++ 2 files changed, 72 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json diff --git a/advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json b/advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json new file mode 100644 index 00000000000..ff7398ce48d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jcg6-gqfh-q5rq/GHSA-jcg6-gqfh-q5rq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcg6-gqfh-q5rq", + "modified": "2025-03-10T03:30:51Z", + "published": "2025-03-10T03:30:51Z", + "aliases": [ + "CVE-2024-41724" + ], + "details": "Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. \n\n\n\n\nThis issue affects all versions of Gallagher Command Centre prior to 9.20.1043.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41724" + }, + { + "type": "WEB", + "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-41724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T03:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json b/advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json new file mode 100644 index 00000000000..d97502e5301 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r25q-23cf-rhp4/GHSA-r25q-23cf-rhp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r25q-23cf-rhp4", + "modified": "2025-03-10T03:30:51Z", + "published": "2025-03-10T03:30:51Z", + "aliases": [ + "CVE-2024-43107" + ], + "details": "Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin.\nThis issue effects Gallagher MIPS Plugin v4.0 prior to v4.0.32, all versions of v3.0 and prior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43107" + }, + { + "type": "WEB", + "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-43107" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-10T03:15:26Z" + } +} \ No newline at end of file