Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Controller 7000 OnelinkAI | 10/7/2025 | 17/6/2026 | Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connected. This issue… | |
| Aplazada | Media (4.6) | 0.32% | — | Controller 6000AIController 7000AI | 12/12/2024 | 17/6/2026 | Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected devices, require a device reboot to resolve. This issue affects:… | |
| Aplazada | Media (4.6) | 0.23% | — | Salto Controller 6000AISalto Controller 7000AI | 11/9/2024 | 17/6/2026 | Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring to instigate a reboot leading to a denial of service. This issue affects: Controller 6000 and Controller 7000 9.10 prior to vCR9.10.240816a… | |
| Aplazada | Media (6.5) | 0.34% | — | Gallagher Controller 6000AIGallagher Controller 7000AI | 11/9/2024 | 17/6/2026 | Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to reboot the Controller, causing a Denial of Service. Gallagher recommend the diagnostic web page is not enabled (default is off) unless advised by… | |
| Aplazada | Media (6.1) | 0.28% | — | Controller 6000AIController 7000AI | 11/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration during an authenticated Operator's session. This issue affects: Controller 6000 and Controller 7000 9.10 prior to vCR9.10.240816a… | |
| Aplazada | Media (4.6) | 0.19% | — | Gallagher Controller 6000AIGallagher Controller 7000AIGallagher Aperio Communication HUBAI | 11/7/2024 | 17/6/2026 | Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks connected via Aperio Communication Hubs to momentarily allow free access. This issue affects: Gallagher Controller 6000 and 7000 9.10 prior to… | |
| Aplazada | Media (6.3) | 0.17% | — | Controller 6000AIController 7000AI | 11/7/2024 | 17/6/2026 | External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code execution. This issue affects: 9.10 prior to vCR9.10.240520a (distributed in 9.10.1268(MR1)), 9.00 prior to vCR9.00.240521a (distributed in… | |
| Aplazada | Media (6.8) | 0.31% | — | Gallagher Controller 6000AIGallagher Controller 7000AI | 11/7/2024 | 17/6/2026 | External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O connections leading to unexpected behavior that in some circumstances could compromise site physical security controls. Gallagher recommend the… | |
| Aplazada | Media (6.2) | 0.17% | — | Gallagher Controller 7000AI | 5/3/2024 | 17/6/2026 | Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface, resulting in a persistent denial of service. This issue affects: All variants of the Gallagher Controller… | |
| Modificada | Media (6.8) | 0.35% | — | Gallagher Controller 7000 Firmware | 18/12/2023 | 17/6/2026 | Incorrect selection of fuse values in the Controller 7000 platform allows an attacker to bypass some protection mechanisms to enable local debug. This issue affects: Gallagher Controller 7000 9.00 prior to vCR9.00.231204b (distributed in 9.00.1507 (MR1)), 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)),… |