Gallagher

Command Centre

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 25.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:49:03

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vE...

  • EPSS 0.15%
  • Veröffentlicht 25.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:44:38

A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)

  • EPSS 0.04%
  • Veröffentlicht 24.07.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:44:47

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60....

  • EPSS 0.11%
  • Veröffentlicht 06.07.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:48

Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designed for public use, to invoke an...

  • EPSS 0.04%
  • Veröffentlicht 18.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:21

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.20...

  • EPSS 0.18%
  • Veröffentlicht 18.11.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:21

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre...

  • EPSS 0.1%
  • Veröffentlicht 18.11.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:18

Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive information from the Command Centre Server. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3); 8.40 v...

  • EPSS 0.24%
  • Veröffentlicht 18.11.2021 18:15:07
  • Zuletzt bearbeitet 21.11.2024 05:51:17

An Incomplete Comparison with Missing Factors vulnerability in the Gallagher Controller allows an attacker to bypass PIV verification. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.13...

  • EPSS 0.01%
  • Veröffentlicht 11.06.2021 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:51:23

Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption key to be discoverable in server memory dumps. This issue affects: Gallagher Command Centre 8.40 versions prior t...

  • EPSS 0.25%
  • Veröffentlicht 11.06.2021 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:51:24

A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected. This issue affects: Gallagher Command Centre 8.40 versions prior to 8...