Gallagher records
53 published records for vendor gallagher.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-285 Improper Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-532 Insertion of Sensitive Information into Log File3
- CWE-316 Cleartext Storage of Sensitive Information in Memory2
- CWE-287 Improper Authentication2
- CWE-296 Improper Following of a Certificate's Chain of Trust2
The weakness classes this vendor ships most often: where to look.
CWEAll records
53 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2019-15294No exploit | An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).gallagher · command centre · CWE-532 | Critical9.8 | — | 1.2% | Aug 28, 2019 |
39Monitor | CVE-2020-16098No exploit | It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8gallagher · command centre · CWE-287 | Critical9.8 | — | 1.1% | Sep 15, 2020 |
39Monitor | CVE-2023-24584No exploit | Controller 6000 buffer overflow via upload feature in web interfacegallagher · controller 6000 firmware · CWE-120 | Critical9.8 | — | 0.5% | Jun 1, 2023 |
36Monitor | CVE-2020-16103No exploit | Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.gallagher · command centre · CWE-704 | High8.8 | — | 2.3% | Dec 14, 2020 |
35Monitor | CVE-2021-23140No exploit | Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Commandgallagher · command centre · CWE-285 | High8.8 | — | 0.9% | Jun 11, 2021 |
35Monitor | CVE-2023-24590No exploit | A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instagallagher · controller 6000 firmware · CWE-134 | High8.8 | — | 0.6% | Dec 18, 2023 |
34Monitor | CVE-2026-25193No exploit | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentiagallagher · active directory sync · CWE-532 | High8.6 | — | 0.1% | May 25, 2026 |
32Monitor | CVE-2020-16102No exploit | Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invagallagher · command centre · CWE-287 | High8.2 | — | 1.0% | Dec 14, 2020 |
32Monitor | CVE-2021-23205No exploit | Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers gallagher · command centre · CWE-116 | High8.1 | — | 0.9% | Jun 11, 2021 |
32Monitor | CVE-2023-23570No exploit | Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undegallagher · command centre · CWE-602 | High8.1 | — | 0.7% | Dec 18, 2023 |
32Monitor | CVE-2024-43690No exploit | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to pergallagher · command centre server · CWE-829 | High8.0 | — | 0.6% | Sep 11, 2024 |
32Monitor | CVE-2021-23162No exploit | Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Cgallagher · command centre mobile connect · CWE-296 | High8.1 | — | 0.4% | Nov 18, 2021 |
31Monitor | CVE-2021-23197No exploit | Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the accountgallagher · command centre · CWE-428 | High7.8 | — | 0.3% | Nov 18, 2021 |
30Monitor | CVE-2020-16101No exploit | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer acgallagher · command centre · CWE-805 | High7.5 | — | 1.0% | Sep 15, 2020 |
30Monitor | CVE-2020-16100No exploit | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to imgallagher · command centre · CWE-404 | High7.5 | — | 1.0% | Sep 15, 2020 |
30Monitor | CVE-2022-26078No exploit | Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.gallagher · controller 6000 firmware · CWE-754 | High7.5 | — | 0.9% | Jul 6, 2022 |
30Monitor | CVE-2021-23146No exploit | An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.gallagher · command centre · CWE-1023 | High7.5 | — | 0.9% | Nov 18, 2021 |
30Monitor | CVE-2020-16096No exploit | In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to gallagher · command centre · CWE-285 | High7.7 | — | 0.8% | Sep 15, 2020 |
30Monitor | CVE-2023-22363No exploit | Access Zone stack overflowgallagher · command centre · CWE-121 | High7.5 | — | 0.6% | Jul 24, 2023 |
28Monitor | CVE-2020-16104No exploit | SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Intgallagher · command centre · CWE-89 | High7.2 | — | 0.9% | Dec 14, 2020 |
28Monitor | CVE-2023-46686No exploit | A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagallagher · command centre · CWE-807 | High7.1 | — | 0.5% | Dec 18, 2023 |
27Monitor | CVE-2021-23155No exploit | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Cegallagher · command centre mobile client · CWE-296 | Medium6.8 | — | 0.5% | Nov 18, 2021 |
27Monitor | CVE-2021-23167No exploit | Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Commgallagher · command centre · CWE-295 | Medium6.8 | — | 0.4% | Nov 18, 2021 |
27Monitor | CVE-2023-6355No exploit | Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local gallagher · controller 7000 firmware · CWE-1253 | Medium6.8 | — | 0.4% | Dec 18, 2023 |
26Monitor | CVE-2019-19802No exploit | In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 priogallagher · command centre · CWE-862 | Medium6.5 | — | 0.8% | Jan 16, 2020 |
- CVE-2019-1529439Monitor
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).
CriticalCVSS 9.8No exploitEPSS 1%gallagher · command centreAug 28, 2019
- CVE-2020-1609839Monitor
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8
CriticalCVSS 9.8No exploitEPSS 1%gallagher · command centreSep 15, 2020
- CVE-2023-2458439Monitor
Controller 6000 buffer overflow via upload feature in web interface
CriticalCVSS 9.8No exploitEPSS 0%gallagher · controller 6000 firmwareJun 1, 2023
- CVE-2020-1610336Monitor
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.
HighCVSS 8.8No exploitEPSS 2%gallagher · command centreDec 14, 2020
- CVE-2021-2314035Monitor
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command
HighCVSS 8.8No exploitEPSS 1%gallagher · command centreJun 11, 2021
- CVE-2023-2459035Monitor
A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some insta
HighCVSS 8.8No exploitEPSS 1%gallagher · controller 6000 firmwareDec 18, 2023
- CVE-2026-2519334Monitor
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentia
HighCVSS 8.6No exploitEPSS 0%gallagher · active directory syncMay 25, 2026
- CVE-2020-1610232Monitor
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with inva
HighCVSS 8.2No exploitEPSS 1%gallagher · command centreDec 14, 2020
- CVE-2021-2320532Monitor
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers
HighCVSS 8.1No exploitEPSS 1%gallagher · command centreJun 11, 2021
- CVE-2023-2357032Monitor
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with unde
HighCVSS 8.1No exploitEPSS 1%gallagher · command centreDec 18, 2023
- CVE-2024-4369032Monitor
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to per
HighCVSS 8.0No exploitEPSS 1%gallagher · command centre serverSep 11, 2024
- CVE-2021-2316232Monitor
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C
HighCVSS 8.1No exploitEPSS 0%gallagher · command centre mobile connectNov 18, 2021
- CVE-2021-2319731Monitor
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account
HighCVSS 7.8No exploitEPSS 0%gallagher · command centreNov 18, 2021
- CVE-2020-1610130Monitor
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer ac
HighCVSS 7.5No exploitEPSS 1%gallagher · command centreSep 15, 2020
- CVE-2020-1610030Monitor
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to im
HighCVSS 7.5No exploitEPSS 1%gallagher · command centreSep 15, 2020
- CVE-2022-2607830Monitor
Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.
HighCVSS 7.5No exploitEPSS 1%gallagher · controller 6000 firmwareJul 6, 2022
- CVE-2021-2314630Monitor
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.
HighCVSS 7.5No exploitEPSS 1%gallagher · command centreNov 18, 2021
- CVE-2020-1609630Monitor
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to
HighCVSS 7.7No exploitEPSS 1%gallagher · command centreSep 15, 2020
- CVE-2023-2236330Monitor
Access Zone stack overflow
HighCVSS 7.5No exploitEPSS 1%gallagher · command centreJul 24, 2023
- CVE-2020-1610428Monitor
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Int
HighCVSS 7.2No exploitEPSS 1%gallagher · command centreDec 14, 2020
- CVE-2023-4668628Monitor
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Dia
HighCVSS 7.1No exploitEPSS 1%gallagher · command centreDec 18, 2023
- CVE-2021-2315527Monitor
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce
MediumCVSS 6.8No exploitEPSS 0%gallagher · command centre mobile clientNov 18, 2021
- CVE-2021-2316727Monitor
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Comm
MediumCVSS 6.8No exploitEPSS 0%gallagher · command centreNov 18, 2021
- CVE-2023-635527Monitor
Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local
MediumCVSS 6.8No exploitEPSS 0%gallagher · controller 7000 firmwareDec 18, 2023
- CVE-2019-1980226Monitor
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prio
MediumCVSS 6.5No exploitEPSS 1%gallagher · command centreJan 16, 2020