Gallagher Group Ltd. is a physical security and access-control vendor whose vulnerability footprint centers on a focused line of command and control platforms and networked controller hardware that manage building access, surveillance, and security operations. The exposure recurs across flagship products including Command Centre, the Controller 6000 and 7000 series, and associated mobile clients, with a meaningful share reaching critical severity. The durable signal concentrates in access-control and authorization weaknesses—including improper authorization, SQL injection, and improper certificate validation—that reflect the authentication, database interaction, and credential-management demands of security-appliance firmware and management software. Defenders should prioritize patching this vendor's command and control infrastructure and controller firmware, as these systems sit in the critical path for physical security operations; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gallagher Group Ltd. over time
Of all the CVEs published by Gallagher Group Ltd. as a CNA, 55.7% affect products that Gallagher Group Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Gallagher Group Ltd., 88.6% are self-published by Gallagher Group Ltd. as a CNA.
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-16098CRITICAL It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions o | Sep 15, 2020 | 9.8 | 29 | NO | NO |
CVE-2023-24584CRITICAL
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature.
This issue affects Controller 6000: before vCR8.80.230201a, bef | Jun 1, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-15294CRITICAL An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is install | Aug 28, 2019 | 9.8 | 27 | NO | NO |
CVE-2021-23162HIGH Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallag | Nov 18, 2021 | 8.1 | 26 | NO | NO |
CVE-2021-23205HIGH Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their pr | Jun 11, 2021 | 8.1 | 26 | NO | NO |
CVE-2020-16103HIGH Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre | Dec 14, 2020 | 8.8 | 26 | NO | NO |
CVE-2021-23140HIGH Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Ga | Jun 11, 2021 | 8.8 | 25 | NO | NO |
CVE-2020-16102HIGH Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing t | Dec 14, 2020 | 8.2 | 25 | NO | NO |
CVE-2022-26078HIGH Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 60 | Jul 6, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-23197HIGH Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This | Nov 18, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gallagher Group Ltd..
Media articles that mention a CVE ID that affects a product developed by Gallagher Group Ltd. — matched by CVE ID, not by vendor name.