---
cve: "CVE-2024-43690"
severity: "HIGH"
cvss: 8.0
epss: "60%"
vendor: "Gallagher"
kev: false
exploited: false
published: "2024-09-11 05:15:02"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T13:59:59+02:00"
---

# CVE-2024-43690

> 8.0 HIGH

## Beschreibung

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE).

This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-829** — Inclusion of Functionality from Untrusted Control Sphere
  The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

## Angriffsmuster (CAPEC)

- [CAPEC-175 — Code Inclusion](https://capec.mitre.org/data/definitions/175.html) _(Severity: Very High)_
- [CAPEC-201 — Serialized Data External Linking](https://capec.mitre.org/data/definitions/201.html) _(Severity: High)_
- [CAPEC-228 — DTD Injection](https://capec.mitre.org/data/definitions/228.html) _(Severity: Medium)_
- [CAPEC-251 — Local Code Inclusion](https://capec.mitre.org/data/definitions/251.html) _(Severity: Medium)_
- [CAPEC-252 — PHP Local File Inclusion](https://capec.mitre.org/data/definitions/252.html) _(Severity: Medium)_
- [CAPEC-253 — Remote Code Inclusion](https://capec.mitre.org/data/definitions/253.html)
- [CAPEC-263 — Force Use of Corrupted Files](https://capec.mitre.org/data/definitions/263.html) _(Severity: Medium)_
- [CAPEC-538 — Open-Source Library Manipulation](https://capec.mitre.org/data/definitions/538.html) _(Severity: High)_

## ATT&CK-Techniken

- [T1055 — Process Injection](https://attack.mitre.org/techniques/T1055/)
- [T1195.001 — Supply Chain Compromise: Software Dependencies and Developme](https://attack.mitre.org/techniques/T1195/001/)

## Referenzen

- <https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2024-43690>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-43690) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
