CVE-2020-7215: Gallagher Command Centre

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party integrations such as DVR systems) were logged in the Command Centre event trail. Any authenticated operator with the 'view events' privilege could see the full configuration, including cleartext usernames and passwords, under the event details of a Modified DVR System event.

Affected products

  • Gallagher Command Centre: before 7.80 (fixed in 7.80); from 7.90, before 7.90.991 (fixed in 7.90.991); from 8.00, before 8.00.1161 (fixed in 8.00.1161); from 8.10, before 8.10.1134 (fixed in 8.10.1134); version 7.90.991 only; version 8.00.1161 only; …

Published 2020-01-20. Last modified 2026-06-17.