Command Centre

Gallagher · 43 CVEs

CVE-2026-27844
LOW

Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticate…

Jul 7, 2026

CVE-2026-27790
LOW

Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by…

Jul 7, 2026

CVE-2026-26053
MEDIUM

An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator…

Jul 7, 2026

CVE-2026-25193
HIGH

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Serv…

May 25, 2026

CVE-2026-20757
LOW

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limite…

Mar 3, 2026

CVE-2024-43690
HIGH

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may all…

Sep 11, 2024

CVE-2024-23194
LOW

Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacke…

Jul 11, 2024

CVE-2024-21838
MEDIUM

Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Cent…

Mar 5, 2024

CVE-2024-21815
CRITICAL

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are access…

Mar 5, 2024

CVE-2023-46686
HIGH

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallaghe…

Dec 18, 2023

CVE-2023-23584
MEDIUM

An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to…

Dec 18, 2023

CVE-2023-23576
MEDIUM

Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site…

Dec 18, 2023

CVE-2023-23570
HIGH

Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid con…

Dec 18, 2023

CVE-2023-22439
MEDIUM

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in…

Dec 18, 2023

CVE-2023-23568
MEDIUM

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view P…

Jul 25, 2023

CVE-2023-22363
HIGH

Access Zone stack overflow

Jul 24, 2023

CVE-2023-25074
HIGH

Competency access levels not enforced in the server

Jul 24, 2023

CVE-2023-22428
HIGH

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This…

Jul 24, 2023

CVE-2022-26348
HIGH

Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The W…

Jul 6, 2022

CVE-2021-23193
HIGH

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated un…

Nov 18, 2021

CVE-2021-23197
HIGH

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrar…

Nov 18, 2021

CVE-2021-23167
HIGH

Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive info…

Nov 18, 2021

CVE-2021-23146
HIGH

An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PI…

Nov 18, 2021

CVE-2021-23230
CRITICAL

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command C…

Jun 11, 2021

CVE-2021-23211
MEDIUM

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-…

Jun 11, 2021

Showing 1 to 25 of 43 CVEs