Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated...
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site permissions to make cri...
AI Analyst Comment
Remediation
Update Exposure of Sensitive System Information to an Unauthorized Control Sphere Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Description Summary:
A vulnerability in the Gallagher Morpho integration allows authenticated operators with limited permissions to perform unauthorized critical changes to local Morpho devices.
Executive Summary:
A critical vulnerability in the Gallagher Command Centre Server permits authenticated operators to perform unauthorized actions on Morpho devices, posing a severe risk to site security.
Vulnerability Details
CVE-ID: CVE-2025-47699
Affected Software: Gallagher Command Centre Server
Affected Versions: 8.90 and prior, 9.00 up to 9.00.3831, 9.10 up to 9.10.3672, 9.20 up to 9.20.2819, 9.30 up to 9.30.2482
Vulnerability: This is an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) vulnerability within the Morpho integration component. It allows an authenticated operator with restricted site permissions to bypass intended access controls and manipulate Morpho devices.
Business Impact
The ability for a low-privileged operator to perform unauthorized critical changes on physical security devices presents a high risk to organizational security and operational integrity. Given the CVSS score of 9.9, this vulnerability carries a critical severity rating as it allows for total system compromise, potentially leading to unauthorized access to secured areas or the disruption of physical security systems.
Remediation Plan
Immediate Action: Update the Gallagher Command Centre Server to the latest release or the specific maintenance release (MR) version identified in the vendor advisory (e.g., vEL9.30.2482 or later).
Proactive Monitoring: Review system access logs for suspicious activity originating from operator accounts, specifically focusing on unauthorized configuration changes or unexpected interactions with Morpho devices.
Compensating Controls: Restrict access to the Command Centre Server management interface and enforce the principle of least privilege by auditing and tightening operator permissions until the patch is applied.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of October 23, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The high CVSS score and the nature of the integration flaw suggest that the vulnerability is inherently dangerous if the internal control sphere is breached.
Analyst Recommendation
This vulnerability represents a significant security risk due to the potential for unauthorized control over physical security infrastructure. Administrators must prioritize the application of the provided maintenance releases immediately to prevent potential exploitation by malicious or compromised internal operators.