Записи Gallagher
53 опубликованных записей вендора gallagher.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-285 Improper Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-532 Insertion of Sensitive Information into Log File3
- CWE-316 Cleartext Storage of Sensitive Information in Memory2
- CWE-287 Improper Authentication2
- CWE-296 Improper Following of a Certificate's Chain of Trust2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
53 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2019-15294Эксплойта нет | An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).gallagher · command centre · CWE-532 | Критическая9,8 | — | 1,2 % | 28 авг. 2019 г. |
39Наблюдать | CVE-2020-16098Эксплойта нет | It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8gallagher · command centre · CWE-287 | Критическая9,8 | — | 1,1 % | 15 сент. 2020 г. |
39Наблюдать | CVE-2023-24584Эксплойта нет | Controller 6000 buffer overflow via upload feature in web interfacegallagher · controller 6000 firmware · CWE-120 | Критическая9,8 | — | 0,5 % | 1 июн. 2023 г. |
36Наблюдать | CVE-2020-16103Эксплойта нет | Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.gallagher · command centre · CWE-704 | Высокая8,8 | — | 2,3 % | 14 дек. 2020 г. |
35Наблюдать | CVE-2021-23140Эксплойта нет | Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Commandgallagher · command centre · CWE-285 | Высокая8,8 | — | 0,9 % | 11 июн. 2021 г. |
35Наблюдать | CVE-2023-24590Эксплойта нет | A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instagallagher · controller 6000 firmware · CWE-134 | Высокая8,8 | — | 0,6 % | 18 дек. 2023 г. |
34Наблюдать | CVE-2026-25193Эксплойта нет | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentiagallagher · active directory sync · CWE-532 | Высокая8,6 | — | 0,1 % | 25 мая 2026 г. |
32Наблюдать | CVE-2020-16102Эксплойта нет | Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invagallagher · command centre · CWE-287 | Высокая8,2 | — | 1,0 % | 14 дек. 2020 г. |
32Наблюдать | CVE-2021-23205Эксплойта нет | Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers gallagher · command centre · CWE-116 | Высокая8,1 | — | 0,9 % | 11 июн. 2021 г. |
32Наблюдать | CVE-2023-23570Эксплойта нет | Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undegallagher · command centre · CWE-602 | Высокая8,1 | — | 0,7 % | 18 дек. 2023 г. |
32Наблюдать | CVE-2024-43690Эксплойта нет | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to pergallagher · command centre server · CWE-829 | Высокая8,0 | — | 0,6 % | 11 сент. 2024 г. |
32Наблюдать | CVE-2021-23162Эксплойта нет | Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Cgallagher · command centre mobile connect · CWE-296 | Высокая8,1 | — | 0,4 % | 18 нояб. 2021 г. |
31Наблюдать | CVE-2021-23197Эксплойта нет | Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the accountgallagher · command centre · CWE-428 | Высокая7,8 | — | 0,3 % | 18 нояб. 2021 г. |
30Наблюдать | CVE-2020-16101Эксплойта нет | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer acgallagher · command centre · CWE-805 | Высокая7,5 | — | 1,0 % | 15 сент. 2020 г. |
30Наблюдать | CVE-2020-16100Эксплойта нет | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to imgallagher · command centre · CWE-404 | Высокая7,5 | — | 1,0 % | 15 сент. 2020 г. |
30Наблюдать | CVE-2022-26078Эксплойта нет | Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.gallagher · controller 6000 firmware · CWE-754 | Высокая7,5 | — | 0,9 % | 6 июл. 2022 г. |
30Наблюдать | CVE-2021-23146Эксплойта нет | An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.gallagher · command centre · CWE-1023 | Высокая7,5 | — | 0,9 % | 18 нояб. 2021 г. |
30Наблюдать | CVE-2020-16096Эксплойта нет | In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to gallagher · command centre · CWE-285 | Высокая7,7 | — | 0,8 % | 15 сент. 2020 г. |
30Наблюдать | CVE-2023-22363Эксплойта нет | Access Zone stack overflowgallagher · command centre · CWE-121 | Высокая7,5 | — | 0,6 % | 24 июл. 2023 г. |
28Наблюдать | CVE-2020-16104Эксплойта нет | SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Intgallagher · command centre · CWE-89 | Высокая7,2 | — | 0,9 % | 14 дек. 2020 г. |
28Наблюдать | CVE-2023-46686Эксплойта нет | A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagallagher · command centre · CWE-807 | Высокая7,1 | — | 0,5 % | 18 дек. 2023 г. |
27Наблюдать | CVE-2021-23155Эксплойта нет | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Cegallagher · command centre mobile client · CWE-296 | Средняя6,8 | — | 0,5 % | 18 нояб. 2021 г. |
27Наблюдать | CVE-2021-23167Эксплойта нет | Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Commgallagher · command centre · CWE-295 | Средняя6,8 | — | 0,4 % | 18 нояб. 2021 г. |
27Наблюдать | CVE-2023-6355Эксплойта нет | Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local gallagher · controller 7000 firmware · CWE-1253 | Средняя6,8 | — | 0,4 % | 18 дек. 2023 г. |
26Наблюдать | CVE-2019-19802Эксплойта нет | In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 priogallagher · command centre · CWE-862 | Средняя6,5 | — | 0,8 % | 16 янв. 2020 г. |
- CVE-2019-1529439Наблюдать
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gallagher · command centre28 авг. 2019 г.
- CVE-2020-1609839Наблюдать
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gallagher · command centre15 сент. 2020 г.
- CVE-2023-2458439Наблюдать
Controller 6000 buffer overflow via upload feature in web interface
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %gallagher · controller 6000 firmware1 июн. 2023 г.
- CVE-2020-1610336Наблюдать
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %gallagher · command centre14 дек. 2020 г.
- CVE-2021-2314035Наблюдать
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gallagher · command centre11 июн. 2021 г.
- CVE-2023-2459035Наблюдать
A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some insta
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gallagher · controller 6000 firmware18 дек. 2023 г.
- CVE-2026-2519334Наблюдать
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentia
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %gallagher · active directory sync25 мая 2026 г.
- CVE-2020-1610232Наблюдать
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with inva
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %gallagher · command centre14 дек. 2020 г.
- CVE-2021-2320532Наблюдать
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %gallagher · command centre11 июн. 2021 г.
- CVE-2023-2357032Наблюдать
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with unde
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %gallagher · command centre18 дек. 2023 г.
- CVE-2024-4369032Наблюдать
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to per
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %gallagher · command centre server11 сент. 2024 г.
- CVE-2021-2316232Наблюдать
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %gallagher · command centre mobile connect18 нояб. 2021 г.
- CVE-2021-2319731Наблюдать
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gallagher · command centre18 нояб. 2021 г.
- CVE-2020-1610130Наблюдать
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer ac
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gallagher · command centre15 сент. 2020 г.
- CVE-2020-1610030Наблюдать
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to im
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gallagher · command centre15 сент. 2020 г.
- CVE-2022-2607830Наблюдать
Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gallagher · controller 6000 firmware6 июл. 2022 г.
- CVE-2021-2314630Наблюдать
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gallagher · command centre18 нояб. 2021 г.
- CVE-2020-1609630Наблюдать
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %gallagher · command centre15 сент. 2020 г.
- CVE-2023-2236330Наблюдать
Access Zone stack overflow
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gallagher · command centre24 июл. 2023 г.
- CVE-2020-1610428Наблюдать
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Int
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %gallagher · command centre14 дек. 2020 г.
- CVE-2023-4668628Наблюдать
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Dia
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %gallagher · command centre18 дек. 2023 г.
- CVE-2021-2315527Наблюдать
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gallagher · command centre mobile client18 нояб. 2021 г.
- CVE-2021-2316727Наблюдать
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Comm
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gallagher · command centre18 нояб. 2021 г.
- CVE-2023-635527Наблюдать
Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local
СредняяCVSS 6,8Эксплойта нетEPSS 0 %gallagher · controller 7000 firmware18 дек. 2023 г.
- CVE-2019-1980226Наблюдать
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prio
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gallagher · command centre16 янв. 2020 г.