Vulnerabilities in Gallagher

70 results
Vexday analysis

Com 67 CVEs catalogadas, os produtos Gallagher apresentam um perfil de risco atualmente contido: nenhuma vulnerabilidade consta no catálogo CISA KEV e a taxa de exploração ativa está abaixo da média geral do catálogo. Das 7 falhas de severidade crítica registradas, nenhuma possui PoC pública disponível, o que reduz a superfície de ataque imediata, embora não elimine o risco. O tipo de falha mais recorrente é CWE-285 (controle de acesso impróprio), padrão que merece atenção em ambientes de controle de acesso físico e lógico, segmento central dos produtos da empresa. A CVE mais relevante no momento, CVE-2020-16103, apresenta EPSS de 0,022, indicando baixa probabilidade de exploração ativa a curto prazo, mas deve ser monitorada em conjunto com a vulnerabilidade recente surgida nos últimos 90 dias.

CVE-2026-25193HIGHInsertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentiaEPSS 0.1%CVE-2025-41402MEDIUMClient-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a privileged operator to enter invalid competeEPSS 0.1%CVE-2025-35981MEDIUMExposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to vieEPSS 0.1%CVE-2025-48430MEDIUMUncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged Operator to crash the Command Centre Server atEPSS 0.1%CVE-2021-23211MEDIUMCleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-to-end encryption keyEPSS 0.1%CVE-2025-46406MEDIUMA Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one DEPSS 0.1%CVE-2026-20801MEDIUMCleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher NxWitness VMS integrEPSS 0.1%CVE-2025-48428MEDIUMCleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could allow an authenticated user with access to thEPSS 0.1%CVE-2025-47147MEDIUMCleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with accEPSS 0.1%CVE-2026-20757LOWImproper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service iEPSS 0.1%