CVE-2024-43107

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Mar 10, 2025
CWE ID 295

Summary

CVE-2024-43107 is a vulnerability affecting the Gallagher Milestone Integration Plugin (MIP). This issue, classified as an Improper Certificate Validation (CWE-295), allows unauthenticated messages, including alarm events, to be sent to the Plugin. This vulnerability poses a risk to Gallagher MIP v4.0 prior to v4.0.32 and all versions of v3.0 and earlier. Unauthorized users can potentially exploit this weakness to gain unintended access or manipulate data. Users are strongly encouraged to update their MIP installation to the latest version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share