CVE-2024-41146
Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected devices, require a device reboot to resolve. This issue affects: Controller 6000 and Controller 7000 firmware versions 9.10 prior to vCR9.10.241108a (distributed in 9.10.2149 (MR4)), 9.00 prior to vCR9.00.241108a (distributed in 9.00.2374 (MR5)), 8.90 prior to vCR8.90.241107a (distributed in 8.90.2356 (MR6)), all versions of 8.80 and prior.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.30%
- CWE
- CWE-694
- Published
- 2024-12-12
- Last modified
- 2026-03-13
Affected products
- Gallagher Controller 6000 and Controller 7000
- Gallagher Controller 6000 and Controller 7000
- Gallagher Controller 6000 and Controller 7000
- Gallagher Controller 6000 and Controller 7000
Weakness type
Related vulnerabilities
- CVE-2026-71327 — Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
- CVE-2026-57024 — Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
- CVE-2026-5794 — Vulnerability in Cryptobox allows an authenticated user to trigger an account lockout
- CVE-2025-13609 — Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
- CVE-2025-59048 — OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
- CVE-2022-23721 — PingID integration for Windows login duplicate username collision.
- CVE-2023-20100 — Cisco IOS XE Software for Wireless LAN Controllers CAPWAP Join Denial of Service Vulnerability
- CVE-2021-3436 — BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known