5.5
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Description
Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.
Basic Information
ID
CVE-2025-41402
Source
Gallagher
Published
Oct 23, 2025 at 03:38
Affected Product
Vendor
Gallagher
Product
Command Centre Server
Affected Versions
Gallagher Command Centre Server 0
Gallagher Command Centre Server 9.30
Gallagher Command Centre Server 9.20
Gallagher Command Centre Server 9.10
Gallagher Command Centre Server 9.30
Gallagher Command Centre Server 9.20
Gallagher Command Centre Server 9.10