Vulnerabilities > Gallagher > Command Centre > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-09-15 CVE-2020-16098 Missing Authentication for Critical Function vulnerability in Gallagher Command Centre
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), versions of 8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.
network
low complexity
gallagher CWE-306
critical
9.8
2019-08-28 CVE-2019-15294 Information Exposure Through Log Files vulnerability in Gallagher Command Centre 8.10
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).
network
low complexity
gallagher CWE-532
critical
9.8