Back to Database
Status published
Medium
CVE-2021-23197
Unquoted service path vulnerability in the Gallagher Controller Service allows...
Vulnerability Description
Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ;
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-23197
Credits & Attribution
No credits recorded in the NVD database.
More from Gallagher
View All →CVE-2025-64734
Missing Release of Resource after Effective Lifetime (CWE-772) in the...
Low
2.4
CVE-2025-52578
Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335)...
Medium
5.7
CVE-2025-52457
Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an...
Medium
5.7
CVE-2025-48430
Uncaught Exception (CWE-248) in the Command Centre Server allows an...
Medium
5.5
CVE-2025-48428
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho...
Medium
6.7
Affected Vendor
Gallagher
View all reports →Affected Software
Command Centre
Vulnerable Versions:
8.50
Timeline
Official Publish:
November 18th, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N