Command Centre
Gallagher · 43 CVEs
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticate…
Jul 7, 2026
Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by…
Jul 7, 2026
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator…
Jul 7, 2026
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Serv…
May 25, 2026
Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limite…
Mar 3, 2026
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may all…
Sep 11, 2024
Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacke…
Jul 11, 2024
Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Cent…
Mar 5, 2024
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are access…
Mar 5, 2024
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallaghe…
Dec 18, 2023
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to…
Dec 18, 2023
Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site…
Dec 18, 2023
Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid con…
Dec 18, 2023
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web in…
Dec 18, 2023
Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view P…
Jul 25, 2023
Access Zone stack overflow
Jul 24, 2023
Competency access levels not enforced in the server
Jul 24, 2023
Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This…
Jul 24, 2023
Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The W…
Jul 6, 2022
Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated un…
Nov 18, 2021
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrar…
Nov 18, 2021
Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive info…
Nov 18, 2021
An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PI…
Nov 18, 2021
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command C…
Jun 11, 2021
Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-…
Jun 11, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-27844 | Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a C… | LOW | 0.39% | Jul 7, 2026 |
| CVE-2026-27790 | Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in… | LOW | 0.39% | Jul 7, 2026 |
| CVE-2026-26053 | An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some… | MEDIUM | 0.25% | Jul 7, 2026 |
| CVE-2026-25193 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitiga… | HIGH | 0.14% | May 25, 2026 |
| CVE-2026-20757 | Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centr… | LOW | 0.07% | Mar 3, 2026 |
| CVE-2024-43690 | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Ex… | HIGH | 0.60% | Sep 11, 2024 |
| CVE-2024-23194 | Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Cent… | LOW | 0.15% | Jul 11, 2024 |
| CVE-2024-21838 | Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code inject… | MEDIUM | 0.30% | Mar 5, 2024 |
| CVE-2024-21815 | Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged u… | CRITICAL | 0.33% | Mar 5, 2024 |
| CVE-2023-46686 | A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to… | HIGH | 0.52% | Dec 18, 2023 |
| CVE-2023-23584 | An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would n… | MEDIUM | 0.50% | Dec 18, 2023 |
| CVE-2023-23576 | Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network… | MEDIUM | 0.28% | Dec 18, 2023 |
| CVE-2023-23570 | Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This… | HIGH | 0.67% | Dec 18, 2023 |
| CVE-2023-22439 | Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform… | MEDIUM | 0.51% | Dec 18, 2023 |
| CVE-2023-23568 | Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects… | MEDIUM | 0.31% | Jul 25, 2023 |
| CVE-2023-22363 | Access Zone stack overflow | HIGH | 0.60% | Jul 24, 2023 |
| CVE-2023-25074 | Competency access levels not enforced in the server | HIGH | 0.31% | Jul 24, 2023 |
| CVE-2023-22428 | Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 pr… | HIGH | 0.36% | Jul 24, 2023 |
| CVE-2022-26348 | Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attack… | HIGH | 0.27% | Jul 6, 2022 |
| CVE-2021-23193 | Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensiti… | HIGH | 0.70% | Nov 18, 2021 |
| CVE-2021-23197 | Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Cont… | HIGH | 0.27% | Nov 18, 2021 |
| CVE-2021-23167 | Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server.… | HIGH | 0.40% | Nov 18, 2021 |
| CVE-2021-23146 | An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gall… | HIGH | 0.88% | Nov 18, 2021 |
| CVE-2021-23230 | A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre… | CRITICAL | 0.66% | Jun 11, 2021 |
| CVE-2021-23211 | Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable… | MEDIUM | 0.11% | Jun 11, 2021 |
Showing 1 to 25 of 43 CVEs