Vulnerabilities > Gallagher > Command Centre > 8.10.1253

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-23230 SQL Injection vulnerability in Gallagher Command Centre
A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Centre Operator to modify Command Centre databases undetected.
network
gallagher CWE-89
3.5
2020-12-14 CVE-2020-16102 Missing Authentication for Critical Function vulnerability in Gallagher Command Centre
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart.
network
low complexity
gallagher CWE-306
6.4