Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gallagher
Gallagher command Centre |
|
| Vendors & Products |
Gallagher
Gallagher command Centre |
Thu, 23 Oct 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server: 9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior. | |
| Weaknesses | CWE-602 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Gallagher
Published: 2025-10-23T03:38:22.200Z
Updated: 2025-10-23T14:35:08.110Z
Reserved: 2025-06-17T02:18:59.253Z
Link: CVE-2025-41402
Updated: 2025-10-23T13:26:04.213Z
Status : Awaiting Analysis
Published: 2025-10-23T04:16:40.257
Modified: 2025-10-27T13:20:33.350
Link: CVE-2025-41402
No data.