Skip to main content

Vendor/product archive

gallagher / command_centre CVEs

Beta · best-effort

37 CVEs tagged to gallagher / command_centre6 Critical, 14 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2024-21838

Published Mar 5, 2024

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails genera…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21815

Published Mar 5, 2024

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46686

Published Dec 18, 2023

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure comm…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23584

Published Dec 18, 2023

An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be view…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23576

Published Dec 18, 2023

Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when compete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23570

Published Dec 18, 2023

Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Ga…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23568

Published Jul 25, 2023

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25074

Published Jul 25, 2023

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.9…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22363

Published Jul 25, 2023

A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22428

Published Jul 24, 2023

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26348

Published Jul 6, 2022

Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23197

Published Nov 18, 2021

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23193

Published Nov 18, 2021

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23167

Published Nov 18, 2021

Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects:…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23146

Published Nov 18, 2021

An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23230

Published Jun 11, 2021

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23211

Published Jun 11, 2021

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory du…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23205

Published Jun 11, 2021

Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their p…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23204

Published Jun 11, 2021

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. Thi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23182

Published Jun 11, 2021

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader master keys to be discoverable in server memory dumps. Thi…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23140

Published Jun 11, 2021

Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: G…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-23136

Published Jun 11, 2021

Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gall…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16104

Published Dec 14, 2020

SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' privilege to execute arbitrary…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16103

Published Dec 14, 2020

Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centr…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2