{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-03T16:24:31.712","vulnerabilities":[{"cve":{"id":"CVE-2023-46686","sourceIdentifier":"disclosures@gallagher.com","published":"2023-12-18T22:15:08.967","lastModified":"2026-06-17T06:31:21.653","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"\nA reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. \n\nThis issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).\n\n\n\n"},{"lang":"es","value":"Un usuario privilegiado podría aprovechar la dependencia de entradas sin confianza en una decisión de seguridad para configurar el Gallagher Command Centre Diagnostics Service para utilizar protocolos de comunicación menos seguros. Este problema afecta: Gallagher Diagnostics Service anterior a v1.3.0 (distribuido en 9.00.1507(MR1))."}],"affected":[{"source":"disclosures@gallagher.com","affectedData":[{"vendor":"Gallagher","product":"Command Centre Diagnostics Service","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.3.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"disclosures@gallagher.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":4.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-02-26T20:59:49.981191Z","id":"CVE-2023-46686","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosures@gallagher.com","type":"Secondary","description":[{"lang":"en","value":"CWE-807"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*","versionStartIncluding":"9.00","versionEndExcluding":"9.00.1507","matchCriteriaId":"516A63FB-0145-4EAE-BAF5-2724C1F9F24D"},{"vulnerable":true,"criteria":"cpe:2.3:a:gallagher:command_centre:9.00.1507:-:*:*:*:*:*:*","matchCriteriaId":"7B79DE16-27CB-4D2D-AEDC-3CA2D4ACC5C8"}]}]}],"references":[{"url":"https://security.gallagher.com/Security-Advisories/CVE-2023-46686","source":"disclosures@gallagher.com","tags":["Vendor Advisory"]},{"url":"https://security.gallagher.com/Security-Advisories/CVE-2023-46686","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}