Show filters
55 Total Results
Displaying 51-55 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-7215

Disclosure Date: January 20, 2020 (last updated February 21, 2025)
An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event.
Attacker Value
Unknown

CVE-2019-19801

Disclosure Date: January 17, 2020 (last updated November 27, 2024)
In Gallagher Command Centre Server versions of v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an unprivileged but authenticated user is able to perform a backup of the Command Centre databases.
Attacker Value
Unknown

CVE-2019-19802

Disclosure Date: November 05, 2019 (last updated February 21, 2025)
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OPCUA can view all data that would be replicated in a multi-server setup without privilege checks being applied.
Attacker Value
Unknown

CVE-2019-15294

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visitor management service is installed, the Windows username and password for this service are logged in cleartext to the Command_centre.log file.
0
Attacker Value
Unknown

CVE-2019-12492

Disclosure Date: June 06, 2019 (last updated November 27, 2024)
Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.
0