Gallagher kayıtları
gallagher üreticisine ait 53 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-285 Improper Authorization6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-532 Insertion of Sensitive Information into Log File3
- CWE-316 Cleartext Storage of Sensitive Information in Memory2
- CWE-287 Improper Authentication2
- CWE-296 Improper Following of a Certificate's Chain of Trust2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
53 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2019-15294İstismar yok | An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).gallagher · command centre · CWE-532 | Kritik9,8 | — | %1,2 | 28 Ağu 2019 |
39İzleyin | CVE-2020-16098İstismar yok | It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8gallagher · command centre · CWE-287 | Kritik9,8 | — | %1,1 | 15 Eyl 2020 |
39İzleyin | CVE-2023-24584İstismar yok | Controller 6000 buffer overflow via upload feature in web interfacegallagher · controller 6000 firmware · CWE-120 | Kritik9,8 | — | %0,5 | 1 Haz 2023 |
36İzleyin | CVE-2020-16103İstismar yok | Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.gallagher · command centre · CWE-704 | Yüksek8,8 | — | %2,3 | 14 Ara 2020 |
35İzleyin | CVE-2021-23140İstismar yok | Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Commandgallagher · command centre · CWE-285 | Yüksek8,8 | — | %0,9 | 11 Haz 2021 |
35İzleyin | CVE-2023-24590İstismar yok | A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instagallagher · controller 6000 firmware · CWE-134 | Yüksek8,8 | — | %0,6 | 18 Ara 2023 |
34İzleyin | CVE-2026-25193İstismar yok | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentiagallagher · active directory sync · CWE-532 | Yüksek8,6 | — | %0,1 | 25 May 2026 |
32İzleyin | CVE-2020-16102İstismar yok | Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invagallagher · command centre · CWE-287 | Yüksek8,2 | — | %1,0 | 14 Ara 2020 |
32İzleyin | CVE-2021-23205İstismar yok | Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers gallagher · command centre · CWE-116 | Yüksek8,1 | — | %0,9 | 11 Haz 2021 |
32İzleyin | CVE-2023-23570İstismar yok | Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undegallagher · command centre · CWE-602 | Yüksek8,1 | — | %0,7 | 18 Ara 2023 |
32İzleyin | CVE-2024-43690İstismar yok | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to pergallagher · command centre server · CWE-829 | Yüksek8,0 | — | %0,6 | 11 Eyl 2024 |
32İzleyin | CVE-2021-23162İstismar yok | Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Cgallagher · command centre mobile connect · CWE-296 | Yüksek8,1 | — | %0,4 | 18 Kas 2021 |
31İzleyin | CVE-2021-23197İstismar yok | Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the accountgallagher · command centre · CWE-428 | Yüksek7,8 | — | %0,3 | 18 Kas 2021 |
30İzleyin | CVE-2020-16101İstismar yok | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer acgallagher · command centre · CWE-805 | Yüksek7,5 | — | %1,0 | 15 Eyl 2020 |
30İzleyin | CVE-2020-16100İstismar yok | It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to imgallagher · command centre · CWE-404 | Yüksek7,5 | — | %1,0 | 15 Eyl 2020 |
30İzleyin | CVE-2022-26078İstismar yok | Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.gallagher · controller 6000 firmware · CWE-754 | Yüksek7,5 | — | %0,9 | 6 Tem 2022 |
30İzleyin | CVE-2021-23146İstismar yok | An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.gallagher · command centre · CWE-1023 | Yüksek7,5 | — | %0,9 | 18 Kas 2021 |
30İzleyin | CVE-2020-16096İstismar yok | In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to gallagher · command centre · CWE-285 | Yüksek7,7 | — | %0,8 | 15 Eyl 2020 |
30İzleyin | CVE-2023-22363İstismar yok | Access Zone stack overflowgallagher · command centre · CWE-121 | Yüksek7,5 | — | %0,6 | 24 Tem 2023 |
28İzleyin | CVE-2020-16104İstismar yok | SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Intgallagher · command centre · CWE-89 | Yüksek7,2 | — | %0,9 | 14 Ara 2020 |
28İzleyin | CVE-2023-46686İstismar yok | A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagallagher · command centre · CWE-807 | Yüksek7,1 | — | %0,5 | 18 Ara 2023 |
27İzleyin | CVE-2021-23155İstismar yok | Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Cegallagher · command centre mobile client · CWE-296 | Orta6,8 | — | %0,5 | 18 Kas 2021 |
27İzleyin | CVE-2021-23167İstismar yok | Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Commgallagher · command centre · CWE-295 | Orta6,8 | — | %0,4 | 18 Kas 2021 |
27İzleyin | CVE-2023-6355İstismar yok | Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local gallagher · controller 7000 firmware · CWE-1253 | Orta6,8 | — | %0,4 | 18 Ara 2023 |
26İzleyin | CVE-2019-19802İstismar yok | In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 priogallagher · command centre · CWE-862 | Orta6,5 | — | %0,8 | 16 Oca 2020 |
- CVE-2019-1529439İzleyin
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).
KritikCVSS 9,8İstismar yokEPSS %1gallagher · command centre28 Ağu 2019
- CVE-2020-1609839İzleyin
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8
KritikCVSS 9,8İstismar yokEPSS %1gallagher · command centre15 Eyl 2020
- CVE-2023-2458439İzleyin
Controller 6000 buffer overflow via upload feature in web interface
KritikCVSS 9,8İstismar yokEPSS %0gallagher · controller 6000 firmware1 Haz 2023
- CVE-2020-1610336İzleyin
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.
YüksekCVSS 8,8İstismar yokEPSS %2gallagher · command centre14 Ara 2020
- CVE-2021-2314035İzleyin
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command
YüksekCVSS 8,8İstismar yokEPSS %1gallagher · command centre11 Haz 2021
- CVE-2023-2459035İzleyin
A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some insta
YüksekCVSS 8,8İstismar yokEPSS %1gallagher · controller 6000 firmware18 Ara 2023
- CVE-2026-2519334İzleyin
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentia
YüksekCVSS 8,6İstismar yokEPSS %0gallagher · active directory sync25 May 2026
- CVE-2020-1610232İzleyin
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with inva
YüksekCVSS 8,2İstismar yokEPSS %1gallagher · command centre14 Ara 2020
- CVE-2021-2320532İzleyin
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers
YüksekCVSS 8,1İstismar yokEPSS %1gallagher · command centre11 Haz 2021
- CVE-2023-2357032İzleyin
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with unde
YüksekCVSS 8,1İstismar yokEPSS %1gallagher · command centre18 Ara 2023
- CVE-2024-4369032İzleyin
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to per
YüksekCVSS 8,0İstismar yokEPSS %1gallagher · command centre server11 Eyl 2024
- CVE-2021-2316232İzleyin
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C
YüksekCVSS 8,1İstismar yokEPSS %0gallagher · command centre mobile connect18 Kas 2021
- CVE-2021-2319731İzleyin
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account
YüksekCVSS 7,8İstismar yokEPSS %0gallagher · command centre18 Kas 2021
- CVE-2020-1610130İzleyin
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer ac
YüksekCVSS 7,5İstismar yokEPSS %1gallagher · command centre15 Eyl 2020
- CVE-2020-1610030İzleyin
It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to im
YüksekCVSS 7,5İstismar yokEPSS %1gallagher · command centre15 Eyl 2020
- CVE-2022-2607830İzleyin
Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.
YüksekCVSS 7,5İstismar yokEPSS %1gallagher · controller 6000 firmware6 Tem 2022
- CVE-2021-2314630İzleyin
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.
YüksekCVSS 7,5İstismar yokEPSS %1gallagher · command centre18 Kas 2021
- CVE-2020-1609630İzleyin
In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to
YüksekCVSS 7,7İstismar yokEPSS %1gallagher · command centre15 Eyl 2020
- CVE-2023-2236330İzleyin
Access Zone stack overflow
YüksekCVSS 7,5İstismar yokEPSS %1gallagher · command centre24 Tem 2023
- CVE-2020-1610428İzleyin
SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Int
YüksekCVSS 7,2İstismar yokEPSS %1gallagher · command centre14 Ara 2020
- CVE-2023-4668628İzleyin
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Dia
YüksekCVSS 7,1İstismar yokEPSS %1gallagher · command centre18 Ara 2023
- CVE-2021-2315527İzleyin
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce
OrtaCVSS 6,8İstismar yokEPSS %0gallagher · command centre mobile client18 Kas 2021
- CVE-2021-2316727İzleyin
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Comm
OrtaCVSS 6,8İstismar yokEPSS %0gallagher · command centre18 Kas 2021
- CVE-2023-635527İzleyin
Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local
OrtaCVSS 6,8İstismar yokEPSS %0gallagher · controller 7000 firmware18 Ara 2023
- CVE-2019-1980226İzleyin
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prio
OrtaCVSS 6,5İstismar yokEPSS %1gallagher · command centre16 Oca 2020