Skip to main content

Vendor archive

gallagher CVEs

Beta · best-effort

44 CVEs tagged to vendor gallagher7 Critical, 18 High, 17 Medium, 2 Low, 0 Unrated.

CVE-2024-21838

Published Mar 5, 2024

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails genera…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21815

Published Mar 5, 2024

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46686

Published Dec 18, 2023

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure comm…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23584

Published Dec 18, 2023

An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be view…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23576

Published Dec 18, 2023

Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when compete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23570

Published Dec 18, 2023

Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Ga…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23568

Published Jul 25, 2023

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25074

Published Jul 25, 2023

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.9…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22363

Published Jul 25, 2023

A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22428

Published Jul 24, 2023

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26348

Published Jul 6, 2022

Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23197

Published Nov 18, 2021

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23193

Published Nov 18, 2021

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23167

Published Nov 18, 2021

Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects:…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23146

Published Nov 18, 2021

An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23230

Published Jun 11, 2021

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23211

Published Jun 11, 2021

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory du…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 44 CVEsPage 1 of 2