İçeriğe atla
Noroxi

Gallagher kayıtları

gallagher üreticisine ait 53 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

53 kayıt
  • CVE-2019-15294
    39İzleyin

    An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).

    KritikCVSS 9,8İstismar yokEPSS %1

    gallagher · command centre28 Ağu 2019

  • CVE-2020-16098
    39İzleyin

    It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8

    KritikCVSS 9,8İstismar yokEPSS %1

    gallagher · command centre15 Eyl 2020

  • CVE-2023-24584
    39İzleyin

    Controller 6000 buffer overflow via upload feature in web interface

    KritikCVSS 9,8İstismar yokEPSS %0

    gallagher · controller 6000 firmware1 Haz 2023

  • CVE-2020-16103
    36İzleyin

    Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution.

    YüksekCVSS 8,8İstismar yokEPSS %2

    gallagher · command centre14 Ara 2020

  • CVE-2021-23140
    35İzleyin

    Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command

    YüksekCVSS 8,8İstismar yokEPSS %1

    gallagher · command centre11 Haz 2021

  • CVE-2023-24590
    35İzleyin

    A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some insta

    YüksekCVSS 8,8İstismar yokEPSS %1

    gallagher · controller 6000 firmware18 Ara 2023

  • CVE-2026-25193
    34İzleyin

    Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentia

    YüksekCVSS 8,6İstismar yokEPSS %0

    gallagher · active directory sync25 May 2026

  • CVE-2020-16102
    32İzleyin

    Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with inva

    YüksekCVSS 8,2İstismar yokEPSS %1

    gallagher · command centre14 Ara 2020

  • CVE-2021-23205
    32İzleyin

    Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers

    YüksekCVSS 8,1İstismar yokEPSS %1

    gallagher · command centre11 Haz 2021

  • CVE-2023-23570
    32İzleyin

    Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with unde

    YüksekCVSS 8,1İstismar yokEPSS %1

    gallagher · command centre18 Ara 2023

  • CVE-2024-43690
    32İzleyin

    Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to per

    YüksekCVSS 8,0İstismar yokEPSS %1

    gallagher · command centre server11 Eyl 2024

  • CVE-2021-23162
    32İzleyin

    Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command C

    YüksekCVSS 8,1İstismar yokEPSS %0

    gallagher · command centre mobile connect18 Kas 2021

  • CVE-2021-23197
    31İzleyin

    Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account

    YüksekCVSS 7,8İstismar yokEPSS %0

    gallagher · command centre18 Kas 2021

  • CVE-2020-16101
    30İzleyin

    It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer ac

    YüksekCVSS 7,5İstismar yokEPSS %1

    gallagher · command centre15 Eyl 2020

  • CVE-2020-16100
    30İzleyin

    It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service's DCOM websocket thread due to im

    YüksekCVSS 7,5İstismar yokEPSS %1

    gallagher · command centre15 Eyl 2020

  • CVE-2022-26078
    30İzleyin

    Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address.

    YüksekCVSS 7,5İstismar yokEPSS %1

    gallagher · controller 6000 firmware6 Tem 2022

  • CVE-2021-23146
    30İzleyin

    An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification.

    YüksekCVSS 7,5İstismar yokEPSS %1

    gallagher · command centre18 Kas 2021

  • CVE-2020-16096
    30İzleyin

    In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to

    YüksekCVSS 7,7İstismar yokEPSS %1

    gallagher · command centre15 Eyl 2020

  • CVE-2023-22363
    30İzleyin

    Access Zone stack overflow

    YüksekCVSS 7,5İstismar yokEPSS %1

    gallagher · command centre24 Tem 2023

  • CVE-2020-16104
    28İzleyin

    SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Int

    YüksekCVSS 7,2İstismar yokEPSS %1

    gallagher · command centre14 Ara 2020

  • CVE-2023-46686
    28İzleyin

    A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Dia

    YüksekCVSS 7,1İstismar yokEPSS %1

    gallagher · command centre18 Ara 2023

  • CVE-2021-23155
    27İzleyin

    Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Ce

    OrtaCVSS 6,8İstismar yokEPSS %0

    gallagher · command centre mobile client18 Kas 2021

  • CVE-2021-23167
    27İzleyin

    Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Comm

    OrtaCVSS 6,8İstismar yokEPSS %0

    gallagher · command centre18 Kas 2021

  • CVE-2023-6355
    27İzleyin

    Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local

    OrtaCVSS 6,8İstismar yokEPSS %0

    gallagher · controller 7000 firmware18 Ara 2023

  • CVE-2019-19802
    26İzleyin

    In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prio

    OrtaCVSS 6,5İstismar yokEPSS %1

    gallagher · command centre16 Oca 2020