Gallagher
Gallagher Controller 7000: vulnerabilities and CVEs
Gallagher Controller 7000 has 4 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24972 | Medium (6.5) | 0.34% | — | Sep 11, 2024 | Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to reboot the Controller, causing a Denial of… |
| CVE-2024-23485 | Medium (4.6) | 0.19% | — | Jul 11, 2024 | Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the Controller 6000 and 7000 can lead to secured door locks connected via Aperio Communication Hubs to… |
| CVE-2024-22387 | Medium (6.8) | 0.31% | — | Jul 11, 2024 | External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated user to modify device I/O connections leading to unexpected behavior that in… |
| CVE-2024-22383 | Medium (6.2) | 0.17% | — | Mar 5, 2024 | Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface,… |
Other products by Gallagher
Command Centre · 45Controller 6000 Firmware · 5Controller 6000 · 3Command Centre Server · 2Command Centre Mobile Client · 1Command Centre Mobile Connect · 1Cardholder Sync Utility · 1Command Centre Mobile · 1Aperio Communication HUB · 1Controller 7000 Firmware · 1Diagnostics Service · 1Active Directory Sync · 1