Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-27844

Gravedad CVSS v3.1:
BAJA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
07/07/2026
Última modificación:
14/08/2026

Descripción

*** Pendiente de traducción *** Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service. <br /> Version of Command Centre affected:<br /> <br /> <br /> <br /> <br /> <br /> * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1))<br /> * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3))<br /> * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5))<br /> * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7))<br /> * all versions of 9.10 and prior.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* 9.20.4349 (excluyendo)
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* 9.30.1594 (incluyendo) 9.30.3983 (excluyendo)
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* 9.40.1359 (incluyendo) 9.40.3130 (excluyendo)
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:* 9.50.978 (incluyendo) 9.50.1587 (excluyendo)
cpe:2.3:h:gallagher:controller_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:gallagher:controller_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:gallagher:controller_7000_enhanced:-:*:*:*:*:*:*:*
cpe:2.3:h:gallagher:controller_7000_high_security:-:*:*:*:*:*:*:*
cpe:2.3:h:gallagher:controller_7000_single_door:-:*:*:*:*:*:*:*
cpe:2.3:h:gallagher:controller_7000_two_door:-:*:*:*:*:*:*:*


Referencias a soluciones, herramientas e información