Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gallagher Group Ltd.

First CVE: Jun 6, 2019Active for: 7 yearsTotal CVEs: 44
26.4
VTI Score
Low

Gallagher Group Ltd. is a physical security and access-control vendor whose vulnerability footprint centers on a focused line of command and control platforms and networked controller hardware that manage building access, surveillance, and security operations. The exposure recurs across flagship products including Command Centre, the Controller 6000 and 7000 series, and associated mobile clients, with a meaningful share reaching critical severity. The durable signal concentrates in access-control and authorization weaknesses—including improper authorization, SQL injection, and improper certificate validation—that reflect the authentication, database interaction, and credential-management demands of security-appliance firmware and management software. Defenders should prioritize patching this vendor's command and control infrastructure and controller firmware, as these systems sit in the critical path for physical security operations; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gallagher Group Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2019
7 years ago
Most Recent CVE
Mar 5, 2024
870 days ago

Self-Reporting Analysis

Of all the CVEs published by Gallagher Group Ltd. as a CNA, 55.7% affect products that Gallagher Group Ltd. develops as a vendor.

55.7%
44.3%
Self-reported: 39 (55.7%)
Third-party: 31 (44.3%)

Of all the CVEs published that affect products developed by Gallagher Group Ltd., 88.6% are self-published by Gallagher Group Ltd. as a CNA.

88.6%
11.4%
Self-published: 39 (88.6%)
Other CNAs: 5 (11.4%)

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-16098CRITICAL
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions o
Sep 15, 20209.829NONO
CVE-2023-24584CRITICAL
Controller 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: before vCR8.80.230201a, bef
Jun 1, 20239.828NONO
CVE-2019-15294CRITICAL
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is install
Aug 28, 20199.827NONO
CVE-2021-23162HIGH
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallag
Nov 18, 20218.126NONO
CVE-2021-23205HIGH
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their pr
Jun 11, 20218.126NONO
CVE-2020-16103HIGH
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre
Dec 14, 20208.826NONO
CVE-2021-23140HIGH
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator. This issue affects: Ga
Jun 11, 20218.825NONO
CVE-2020-16102HIGH
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing t
Dec 14, 20208.225NONO
CVE-2022-26078HIGH
Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 60
Jul 6, 20227.524NONO
CVE-2021-23197HIGH
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This
Nov 18, 20217.824NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
57%
36%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (13.6%)
Network34 (77.3%)
Unknown0 (0.0%)
Physical4 (9.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (90.9%)
High4 (9.1%)
Unknown0 (0.0%)
User Interaction
None41 (93.2%)
Unknown0 (0.0%)
Required3 (6.8%)
Privileges Required
Low23 (52.3%)
High3 (6.8%)
None18 (40.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gallagher Group Ltd..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gallagher Group Ltd. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gallagher Group Ltd.'s Products

View all 2 CNAs →

Top CWEs