CyberRota Analysis
AI-GeneratedThe Controller 6000 and Controller 7000 diagnostic web interface is vulnerable to an uncaught exception that allows authenticated operators to send specific requests, resulting in a temporary denial of service through a controller restart. This issue affects multiple versions of the Command Centre software, specifically those prior to designated patch releases. Organizations using these affected versions should prioritize remediation to prevent potential disruptions in service.
Original NVD Description
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.