Vulnerabilities > Gallagher > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-06-01 CVE-2023-24584 Classic Buffer Overflow vulnerability in Gallagher Controller 6000 Firmware
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature.
network
low complexity
gallagher CWE-120
critical
9.8
2020-09-15 CVE-2020-16098 Missing Authentication for Critical Function vulnerability in Gallagher Command Centre
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), versions of 8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.
network
low complexity
gallagher CWE-306
critical
9.8
2019-08-28 CVE-2019-15294 Information Exposure Through Log Files vulnerability in Gallagher Command Centre 8.10
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2).
network
low complexity
gallagher CWE-532
critical
9.8