Back to Database
Status published
High
CVE-2024-43107
Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin...
Vulnerability Description
Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin. This issue effects Gallagher MIPS Plugin v4.0 prior to v4.0.32, all versions of v3.0 and prior.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-43107
Credits & Attribution
No credits recorded in the NVD database.
More from Gallagher
View All →CVE-2025-64734
Missing Release of Resource after Effective Lifetime (CWE-772) in the...
Low
2.4
CVE-2025-52578
Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335)...
Medium
5.7
CVE-2025-52457
Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an...
Medium
5.7
CVE-2025-48430
Uncaught Exception (CWE-248) in the Command Centre Server allows an...
Medium
5.5
CVE-2025-48428
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho...
Medium
6.7
Affected Vendor
Gallagher
View all reports →Affected Software
Milestone Integration Plugin
Vulnerable Versions:
4.0, 0
Timeline
Official Publish:
March 10th, 2025
Last Modified:
March 10th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L