CVE-2024-41724: Gallagher Command Centre Server

High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.

Affected products

  • Gallagher Command Centre Server: before 9.20.1043 (fixed in 9.20.1043)

Published 2025-03-10. Last modified 2026-06-17.