CVE-2020-16101: Gallagher Command Centre

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

It is possible for an unauthenticated remote DCOM websocket connection to crash the Command Centre service due to an out-of-bounds buffer access. Affected versions are v8.20 prior to v8.20.1166(MR3), v8.10 prior to v8.10.1211(MR5), v8.00 prior to v8.00.1228(MR6), all versions of 7.90 and earlier.

Affected products

  • Gallagher Command Centre: from 8.00, before 8.00.1228 (fixed in 8.00.1228); from 8.10, before 8.10.1211 (fixed in 8.10.1211); from 8.20, before 8.20.1166 (fixed in 8.20.1166); version 8.00.1228 only; version 8.10.1211 only; version 8.20.1166 only

Published 2020-09-15. Last modified 2026-06-17.