CVE-2020-16096: Gallagher Command Centre

High severity, CVSS 7.7. EPSS: 0.8% chance of exploitation in the next 30 days.

In Gallagher Command Centre versions 8.10 prior to 8.10.1134(MR4), 8.00 prior to 8.00.1161(MR5), 7.90 prior to 7.90.991(MR5), 7.80 prior to 7.80.960(MR2), 7.70 and earlier, any operator account has access to all data that would be replicated if the system were to be (or is) attached to a multi-server environment. This can include plain text credentials for DVR systems and card details used for physical access/alarm/perimeter components.

Affected products

  • Gallagher Command Centre: from 7.80, before 7.80.960 (fixed in 7.80.960); from 7.90, before 7.90.991 (fixed in 7.90.991); from 8.00, before 8.00.1161 (fixed in 8.00.1161); from 8.10, before 8.10.1134 (fixed in 8.10.1134); version 7.80.960 only; version 7.90.991 only; …

Published 2020-09-15. Last modified 2026-06-17.