Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Command Centre MEDIUM 5.3
CVE-2026-26053

An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to pe…

Mitigation only
Fix from $1,600 2026-07-07
Active Directory Sync HIGH 8.6
CVE-2026-25193

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposu…

Mitigation only
Fix from $1,950 2026-05-25
Command Centre Mobile MEDIUM 5.7
CVE-2025-47147

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a …

Fix: 9.40.123+
Fix from $1,600 2026-03-03
Hanwha Vms Integration MEDIUM 5.6
CVE-2026-20801

Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrations al…

Mitigation only
Fix from $1,600 2026-03-03
Command Centre MEDIUM 6.5
CVE-2024-21815

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unpr…

Fix: 8.70.2526 / 8.80.1526+
Fix from $1,600 2024-03-05
Command Centre MEDIUM 5.4
CVE-2024-21838

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML c…

Fix: 8.70.2526 / 8.80.1526+
Fix from $1,600 2024-03-05
Controller 7000 Firmware MEDIUM 6.8
CVE-2023-6355

Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. T…

Fix: 8.70.231204a / 8.80.231204a+
Fix from $1,600 2023-12-18
Controller 6000 Firmware HIGH 8.8
CVE-2023-24590

A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash t…

Fix: 8.60.231116a+
Fix from $1,950 2023-12-18
Command Centre HIGH 8.1
CVE-2023-23570

Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined beha…

Fix: 8.90.1620+
Fix from $1,950 2023-12-18
Command Centre HIGH 7.1
CVE-2023-46686

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics S…

Fix: 9.00.1507+
Fix from $1,950 2023-12-18
Command Centre MEDIUM 5.4
CVE-2023-23568

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This iss…

Fix: 8.50.2831 / 8.60.2347+
Fix from $1,600 2023-07-25
Command Centre HIGH 7.5
CVE-2023-22363

A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Acc…

Fix: 8.80.1192+
Fix from $1,950 2023-07-25
Command Centre MEDIUM 5.4
CVE-2023-25074

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue …

Fix: 8.50.2831 / 8.60.2347+
Fix from $1,600 2023-07-25
Command Centre MEDIUM 6.5
CVE-2023-22428

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre:…

Fix: 8.50.2831 / 8.60.2347+
Fix from $1,600 2023-07-24
Controller 6000 Firmware CRITICAL 9.8
CVE-2023-24584

Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 600…

Fix: 8.50.230201a / 8.60.230201b+
Fix from $2,300 2023-06-01
Controller 6000 Firmware HIGH 7.5
CVE-2022-26078

Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Ga…

Fix: 8.30.220303a / 8.40.220303a+
Fix from $1,950 2022-07-06
Command Centre MEDIUM 5.5
CVE-2022-26348

Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows…

Fix: 8.30.1470 / 8.40.2216+
Fix from $1,600 2022-07-06
Command Centre HIGH 7.8
CVE-2021-23197

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that run…

Fix: 8.50.2048+
Fix from $1,950 2021-11-18
Command Centre MEDIUM 6.5
CVE-2021-23193

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrie…

Fix: 8.20.1291 / 8.30.1454+
Fix from $1,600 2021-11-18
Command Centre Mobile Connect HIGH 8.1
CVE-2021-23162

Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Ser…

Fix: 15.04.040+
Fix from $1,950 2021-11-18
Command Centre Mobile Client MEDIUM 6.8
CVE-2021-23155

Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Serv…

Fix: 8.60.065+
Fix from $1,600 2021-11-18
Command Centre MEDIUM 6.8
CVE-2021-23167

Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centr…

Fix: 8.30.1454 / 8.40.2063+
Fix from $1,600 2021-11-18
Command Centre HIGH 7.5
CVE-2021-23146

An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue aff…

Fix: 8.10.1284 / 8.20.1259+
Fix from $1,950 2021-11-18
Command Centre HIGH 8.8
CVE-2021-23140

Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre O…

Fix: 8.20.1259 / 8.30.1359+
Fix from $1,950 2021-06-11
Command Centre HIGH 8.1
CVE-2021-23205

Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other…

Fix: 8.20.1259 / 8.30.1359+
Fix from $1,950 2021-06-11
Command Centre MEDIUM 6.5
CVE-2021-23204

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to…

Fix: 8.30.1359 / 8.40.1888+
Fix from $1,600 2021-06-11
Command Centre MEDIUM 6.5
CVE-2021-23136

Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Oper…

Fix: 8.20.1259 / 8.30.1359+
Fix from $1,600 2021-06-11
Command Centre HIGH 8.8
CVE-2020-16103

Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue af…

Fix: 8.10.1211 / 8.20.1166+
Fix from $1,950 2020-12-14
Command Centre HIGH 8.2
CVE-2020-16102

Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid confi…

Fix: 7.90.0 / 8.00.1252+
Fix from $1,950 2020-12-14
Command Centre HIGH 7.2
CVE-2020-16104

SQL Injection vulnerability in Enterprise Data Interface of Gallagher Command Centre allows a remote attacker with 'Edit Enterprise Data Interfaces' …

Fix: 7.90.0 / 8.00.1228+
Fix from $1,950 2020-12-14