CVE-2024-21815: Gallagher Command Centre

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6),  all version of 8.60 and prior.

Affected products

  • Gallagher Command Centre: up to and including 8.60; from 8.70, before 8.70.2526 (fixed in 8.70.2526); from 8.80, before 8.80.1526 (fixed in 8.80.1526); from 8.90, before 8.90.1751 (fixed in 8.90.1751); from 9.00, before 9.00.1774 (fixed in 9.00.1774)

Published 2024-03-05. Last modified 2026-06-17.