Gallagher

Command Centre

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.67%
  • Veröffentlicht 18.12.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:46:26

Client-Side enforcement of Server-Side security for the Command Centre server could be bypassed and lead to invalid configuration with undefined behavior. This issue affects: Gallagher Command Centre 8.90 prior to vEL8.90.1620 (MR2), all versions ...

  • EPSS 0.28%
  • Veröffentlicht 18.12.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 07:46:27

Incorrect behavior order in the Command Centre Server could allow privileged users to gain physical access to the site for longer than intended after a network outage when competencies are used in the access decision. This issue affects: Gallagher...

  • EPSS 0.52%
  • Veröffentlicht 18.12.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:29:04

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Servi...

  • EPSS 0.51%
  • Veröffentlicht 18.12.2023 22:15:07
  • Zuletzt bearbeitet 21.11.2024 07:44:48

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Contr...

  • EPSS 0.31%
  • Veröffentlicht 25.07.2023 02:15:09
  • Zuletzt bearbeitet 21.11.2024 07:46:26

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL 8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2...

  • EPSS 0.31%
  • Veröffentlicht 25.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:49:03

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.90 prior to vEL8.90.1318 (MR1), vEL8.80 prior to vEL8.80.1192 (MR2), vE...

  • EPSS 0.61%
  • Veröffentlicht 25.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:44:38

A stack-based buffer overflow in the Command Centre Server allows an attacker to cause a denial of service attack via assigning cardholders to an Access Group. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2)

  • EPSS 0.37%
  • Veröffentlicht 24.07.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 07:44:47

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60....

  • EPSS 0.27%
  • Veröffentlicht 06.07.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:48

Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designed for public use, to invoke an...

  • EPSS 0.26%
  • Veröffentlicht 18.11.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:51:21

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.20...