CVE-2025-35983
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-10

Last updated on: 2025-07-10

Assigner: Gallagher Group Ltd.

Description
Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connected. This issue affects Controller 7000: 9.30 prior to vCR9.30.250624a (distributed in 9.30.1871 (MR1)).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-10
Last Modified
2025-07-10
Generated
2026-05-07
AI Q&A
2025-07-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
gallagher controller_7000 9.30
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an improper certificate validation issue (CWE-295) in the Controller 7000 OneLink implementation. It allows an unprivileged attacker to perform a limited denial of service or privileged overrides during the initial configuration of the Controller. However, once the Controllers are connected, there is no risk from this vulnerability.


How can this vulnerability impact me? :

The vulnerability can allow an unprivileged attacker to cause a limited denial of service or perform privileged overrides during the initial configuration phase of the Controller 7000. This could disrupt setup or allow unauthorized configuration changes. There is no impact once the Controllers are connected.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update the Controller 7000 software to version vCR9.30.250624a or later, as this version addresses the improper certificate validation issue. Avoid using affected versions prior to this update during initial configuration.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart