CVE-2026-27844
- EPSS 0.23%
- Veröffentlicht 07.07.2026 03:49:34
- Zuletzt bearbeitet 14.08.2026 18:51:18
Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service....
CVE-2026-27790
- EPSS 0.23%
- Veröffentlicht 07.07.2026 03:49:10
- Zuletzt bearbeitet 14.08.2026 18:51:31
Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to...
CVE-2026-26053
- EPSS 0.15%
- Veröffentlicht 07.07.2026 03:48:47
- Zuletzt bearbeitet 18.08.2026 15:54:05
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centr...
CVE-2026-25193
- EPSS 0.14%
- Veröffentlicht 25.05.2026 05:28:14
- Zuletzt bearbeitet 17.08.2026 18:21:14
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account...
CVE-2026-20757
- EPSS 0.07%
- Veröffentlicht 03.03.2026 03:15:54
- Zuletzt bearbeitet 18.08.2026 15:54:36
Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9...
- EPSS 0.6%
- Veröffentlicht 11.09.2024 05:15:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9...
CVE-2024-23194
- EPSS 0.15%
- Veröffentlicht 11.07.2024 03:15:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. This issue affects: Gallagher Command Centre v9.10 prior to vEL9.10.1268 (M...
CVE-2024-21838
- EPSS 0.3%
- Veröffentlicht 05.03.2024 03:15:06
- Zuletzt bearbeitet 10.02.2025 22:33:35
Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre ...
CVE-2024-21815
- EPSS 0.33%
- Veröffentlicht 05.03.2024 03:15:06
- Zuletzt bearbeitet 10.02.2025 22:36:41
Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.9...
CVE-2023-23584
- EPSS 0.5%
- Veröffentlicht 18.12.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:28
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL...