Перейти к содержимому
Noroxi

Записи Gallagher

53 опубликованных записей вендора gallagher.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

53 записей
  • CVE-2019-15294
    39Наблюдать

    An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gallagher · command centre28 авг. 2019 г.

  • CVE-2020-16098
    39Наблюдать

    It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gallagher · command centre15 сент. 2020 г.

  • CVE-2023-24584
    39Наблюдать

    Controller 6000 buffer overflow via upload feature in web interface

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    gallagher · controller 6000 firmware1 июн. 2023 г.

  • CVE-2020-16103
    36Наблюдать

    Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    gallagher · command centre14 дек. 2020 г.

  • CVE-2021-23140
    35Наблюдать

    Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    gallagher · command centre11 июн. 2021 г.

  • CVE-2023-24590
    35Наблюдать

    A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some insta

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    gallagher · controller 6000 firmware18 дек. 2023 г.

  • CVE-2026-25193
    34Наблюдать

    Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentia

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    gallagher · active directory sync25 мая 2026 г.

  • CVE-2020-16102
    32Наблюдать

    Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with inva

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    gallagher · command centre14 дек. 2020 г.

  • CVE-2021-23205
    32Наблюдать

    Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    gallagher · command centre11 июн. 2021 г.

  • CVE-2023-23570
    32Наблюдать

    Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with unde

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    gallagher · command centre18 дек. 2023 г.

  • CVE-2024-43690
    32Наблюдать

    Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to per

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    gallagher · command centre server11 сент. 2024 г.

  • CVE-2021-23162
    32Наблюдать

    Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    gallagher · command centre mobile connect18 нояб. 2021 г.

  • CVE-2021-23197
    31Наблюдать

    Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    gallagher · command centre18 нояб. 2021 г.

  • CVE-2020-16101
    30Наблюдать

    It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer ac

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    gallagher · command centre15 сент. 2020 г.

  • CVE-2020-16100
    30Наблюдать

    It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to im

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    gallagher · command centre15 сент. 2020 г.

  • CVE-2022-26078
    30Наблюдать

    Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    gallagher · controller 6000 firmware6 июл. 2022 г.

  • CVE-2021-23146
    30Наблюдать

    An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    gallagher · command centre18 нояб. 2021 г.

  • CVE-2020-16096
    30Наблюдать

    In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    gallagher · command centre15 сент. 2020 г.

  • CVE-2023-22363
    30Наблюдать

    Access Zone stack overflow

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    gallagher · command centre24 июл. 2023 г.

  • CVE-2020-16104
    28Наблюдать

    SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Int

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    gallagher · command centre14 дек. 2020 г.

  • CVE-2023-46686
    28Наблюдать

    A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Dia

    ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %

    gallagher · command centre18 дек. 2023 г.

  • CVE-2021-23155
    27Наблюдать

    Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    gallagher · command centre mobile client18 нояб. 2021 г.

  • CVE-2021-23167
    27Наблюдать

    Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Comm

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    gallagher · command centre18 нояб. 2021 г.

  • CVE-2023-6355
    27Наблюдать

    Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    gallagher · controller 7000 firmware18 дек. 2023 г.

  • CVE-2019-19802
    26Наблюдать

    In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prio

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    gallagher · command centre16 янв. 2020 г.