Gallagher Group Ltd.

First CVE: Sep 15, 2020Active for: 6 years
70
CVEs Published
More CVEs Published than 65% of tracked CNAs
10.0
Avg CVEs / Year
More Avg CVEs / Year than 54% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Gallagher Group Ltd. as a CNA, 55.7% affect products that Gallagher Group Ltd. develops as a vendor.

55.7%
44.3%
Self-reported: 39Third-party: 31

Of all the CVEs published that affect products developed by Gallagher Group Ltd., 88.6% are self-published by Gallagher Group Ltd. as a CNA.

88.6%
11.4%
Self-published: 39Published by other CNAs: 5

Trends Over Time

The number and severity of CVEs published by Gallagher Group Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2020
5 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

Top CVEs

All CVEs published by Gallagher Group Ltd. as a CNA, regardless of affected vendor or product.

70 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site per
Oct 23, 20259.933NONO
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.  Mitigating Factor: Only si
May 25, 20268.132NONO
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions o
Sep 15, 20209.829NONO
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, bef
Jun 1, 20239.828NONO
Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of G
Mar 10, 20258.727NONO
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they
Jul 7, 20265.326NONO
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallag
Nov 18, 20218.126NONO
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their pr
Jun 11, 20218.126NONO
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre
Dec 14, 20208.826NONO
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Ga
Jun 11, 20218.825NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA70 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local15 (21.4%)
Network44 (62.9%)
Unknown0 (0.0%)
Physical10 (14.3%)
Adjacent Network1 (1.4%)
Attack Complexity
Low57 (81.4%)
High13 (18.6%)
Unknown0 (0.0%)
User Interaction
None62 (88.6%)
Unknown0 (0.0%)
Required8 (11.4%)
Privileges Required
Low30 (42.9%)
High9 (12.9%)
None31 (44.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (70 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Gallagher Group Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Gallagher Group Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs