Skip to content
Noroxi

Gallagher records

53 published records for vendor gallagher.

All records

53 records
  • An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).

    CriticalCVSS 9.8No exploitEPSS 1%

    gallagher · command centreAug 28, 2019

  • It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8

    CriticalCVSS 9.8No exploitEPSS 1%

    gallagher · command centreSep 15, 2020

  • Controller 6000 buffer overflow via upload feature in web interface

    CriticalCVSS 9.8No exploitEPSS 0%

    gallagher · controller 6000 firmwareJun 1, 2023

  • Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.

    HighCVSS 8.8No exploitEPSS 2%

    gallagher · command centreDec 14, 2020

  • Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command

    HighCVSS 8.8No exploitEPSS 1%

    gallagher · command centreJun 11, 2021

  • A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some insta

    HighCVSS 8.8No exploitEPSS 1%

    gallagher · controller 6000 firmwareDec 18, 2023

  • Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentia

    HighCVSS 8.6No exploitEPSS 0%

    gallagher · active directory syncMay 25, 2026

  • Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with inva

    HighCVSS 8.2No exploitEPSS 1%

    gallagher · command centreDec 14, 2020

  • Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers

    HighCVSS 8.1No exploitEPSS 1%

    gallagher · command centreJun 11, 2021

  • Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with unde

    HighCVSS 8.1No exploitEPSS 1%

    gallagher · command centreDec 18, 2023

  • Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to per

    HighCVSS 8.0No exploitEPSS 1%

    gallagher · command centre serverSep 11, 2024

  • Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C

    HighCVSS 8.1No exploitEPSS 0%

    gallagher · command centre mobile connectNov 18, 2021

  • Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account

    HighCVSS 7.8No exploitEPSS 0%

    gallagher · command centreNov 18, 2021

  • It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer ac

    HighCVSS 7.5No exploitEPSS 1%

    gallagher · command centreSep 15, 2020

  • It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to im

    HighCVSS 7.5No exploitEPSS 1%

    gallagher · command centreSep 15, 2020

  • Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.

    HighCVSS 7.5No exploitEPSS 1%

    gallagher · controller 6000 firmwareJul 6, 2022

  • An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.

    HighCVSS 7.5No exploitEPSS 1%

    gallagher · command centreNov 18, 2021

  • In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to

    HighCVSS 7.7No exploitEPSS 1%

    gallagher · command centreSep 15, 2020

  • Access Zone stack overflow

    HighCVSS 7.5No exploitEPSS 1%

    gallagher · command centreJul 24, 2023

  • SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Int

    HighCVSS 7.2No exploitEPSS 1%

    gallagher · command centreDec 14, 2020

  • A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Dia

    HighCVSS 7.1No exploitEPSS 1%

    gallagher · command centreDec 18, 2023

  • Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce

    MediumCVSS 6.8No exploitEPSS 0%

    gallagher · command centre mobile clientNov 18, 2021

  • Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Comm

    MediumCVSS 6.8No exploitEPSS 0%

    gallagher · command centreNov 18, 2021

  • CVE-2023-6355
    27Monitor

    Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local

    MediumCVSS 6.8No exploitEPSS 0%

    gallagher · controller 7000 firmwareDec 18, 2023

  • In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prio

    MediumCVSS 6.5No exploitEPSS 1%

    gallagher · command centreJan 16, 2020