CVE-2025-41402 MEDIUM

CVE-2025-41402

Vendor Gallagher
Product Command Centre Server
Weakness CWE-602 · Client-side enforcement
Published October 23, 2025
Last update October 23, 2025

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competency data, bypassing expiry checks. This issue affects Command Centre Server:  9.30 prior to vEL9.30.2482 (MR2), 9.20 prior to vEL9.20.2819 (MR4), 9.10 prior to vEL9.10.3672 (MR7), all versions of 9.00 and prior.

Key dates

02Disclosure timeline

October 23, 2025 CVE published
October 23, 2025 Record updated