CVE-2024-41724
HIGHCVSS 8.7/10EPSS 0.18%
Last modified
CVE-2024-41724 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-41724?
Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server.
This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.
How severe is CVE-2024-41724?
CVE-2024-41724 has a CVSS score of 8.7/10 (HIGH severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2024-41724?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41719When generating QKView of BIG-IP Next instance from the BIG-…5.5
- CVE-2024-4172A vulnerability classified as problematic was found in idcCM…4.3
- CVE-2024-41720Incorrect permission assignment for critical resource issue …8
- CVE-2024-41721An insufficient boundary validation in the USB code could le…8.1
- CVE-2024-41722In the goTenna Pro ATAK Plugin there is a vulnerability that…6.5
- CVE-2024-41723Undisclosed requests to BIG-IP iControl REST can lead to inf…4.3
- CVE-2024-41725ProGauge MAGLINK LX CONSOLE does not have sufficient filteri…6.1
- CVE-2024-41726Path traversal vulnerability exists in SKYSEA Client View Ve…7.5
- CVE-2024-41727In BIG-IP tenants running on r2000 and r4000 series hardware…7.5
- CVE-2024-41728Due to missing authorization check, SAP NetWeaver Applicatio…2.7
- CVE-2024-41729Due to missing authorization checks, SAP BEx Analyzer allows…4.3
- CVE-2024-4173 A vulnerability in Brocade SANnav exposes Kafka in the wan …9.8
Are you affected by CVE-2024-41724?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
