Gallagher Group Ltd.
First CVE: Sep 15, 2020Active for: 6 years
70
CVEs Published
More CVEs Published than 65% of tracked CNAs
10.0
Avg CVEs / Year
More Avg CVEs / Year than 54% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Gallagher Group Ltd. as a CNA, 55.7% affect products that Gallagher Group Ltd. develops as a vendor.
55.7%
44.3%
Self-reported: 39Third-party: 31
Of all the CVEs published that affect products developed by Gallagher Group Ltd., 88.6% are self-published by Gallagher Group Ltd. as a CNA.
88.6%
11.4%
Self-published: 39Published by other CNAs: 5
Trends Over Time
The number and severity of CVEs published by Gallagher Group Ltd. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2020
5 years ago
Most Recent CVE
Jul 7, 2026
17 days ago
Top CVEs
All CVEs published by Gallagher Group Ltd. as a CNA, regardless of affected vendor or product.
70 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47699CRITICAL Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration could allow an authenticated operator with limited site per | Oct 23, 2025 | 9.9 | 33 | NO | NO |
CVE-2026-25193HIGH Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only si | May 25, 2026 | 8.1 | 32 | NO | NO |
CVE-2020-16098CRITICAL It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions o | Sep 15, 2020 | 9.8 | 29 | NO | NO |
CVE-2023-24584CRITICAL
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature.
This issue affects Controller 6000: before vCR8.80.230201a, bef | Jun 1, 2023 | 9.8 | 28 | NO | NO |
CVE-2024-41724HIGH Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server.
This issue affects all versions of G | Mar 10, 2025 | 8.7 | 27 | NO | NO |
CVE-2026-26053MEDIUM An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they | Jul 7, 2026 | 5.3 | 26 | NO | NO |
CVE-2021-23162HIGH Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallag | Nov 18, 2021 | 8.1 | 26 | NO | NO |
CVE-2021-23205HIGH Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their pr | Jun 11, 2021 | 8.1 | 26 | NO | NO |
CVE-2020-16103HIGH Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre | Dec 14, 2020 | 8.8 | 26 | NO | NO |
CVE-2021-23140HIGH Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Ga | Jun 11, 2021 | 8.8 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA70 CVEs
59%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (21.4%)
Network44 (62.9%)
Unknown0 (0.0%)
Physical10 (14.3%)
Adjacent Network1 (1.4%)
Attack Complexity
Low57 (81.4%)
High13 (18.6%)
Unknown0 (0.0%)
User Interaction
None62 (88.6%)
Unknown0 (0.0%)
Required8 (11.4%)
Privileges Required
Low30 (42.9%)
High9 (12.9%)
None31 (44.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (70 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Gallagher Group Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Gallagher Group Ltd. as a CNA — matched by CVE ID, not by organization name.