9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make critical changes to local Morpho devices.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.
This issue affects Command Centre Server:
9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), 9.00 prior to vEL9.00.3831 (MR8), all versions of 8.90 and prior.
AI Analysis
Exposure of sensitive system information due to insufficient access controls in Gallagher Morpho integration, allowing authenticated operators to make unauthorized changes to local Morpho devices.
Basic Information
ID
CVE-2025-47699
Source
Gallagher
Published
Oct 23, 2025 at 03:38
Affected Product
Vendor
Gallagher
Product
Command Centre Server
Affected Versions
Gallagher Command Centre Server 0
Gallagher Command Centre Server 9.30
Gallagher Command Centre Server 9.20
Gallagher Command Centre Server 9.10
Gallagher Command Centre Server 9.00
Gallagher Command Centre Server 9.30
Gallagher Command Centre Server 9.20
Gallagher Command Centre Server 9.10
Gallagher Command Centre Server 9.00
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
Gallagher
Product
Command Centre Server
Version
9.30 prior to vEL9.30.2482, 9.20 prior to vEL9.20.2819, 9.10 prior to vEL9.10.3672, 9.00 prior to vEL9.00.3831, 8.90 and prior