CVE-2024-42407: Gallagher Command Centre Server
High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4), 9.00 prior to 9.00.2374 (MR5), 8.90 prior to 8.90.2356 (MR6), all versions of 8.80 and prior.
Affected products
- Gallagher Command Centre Server: up to and including 8.80; from 9.10, before 9.10.2149 (MR4) (fixed in 9.10.2149 (MR4)); from 9.00, before 9.00.2374 (MR5) (fixed in 9.00.2374 (MR5)); from 8.90, before 8.90.2356 (MR6) (fixed in 8.90.2356 (MR6))
Published 2024-12-12. Last modified 2026-06-17.