← Vulnerability feed

Vulnerability record · CVE-2022-26078 · published 6 July 2022

CVE-2022-26078: Gallagher controller 6000 firmware vulnerability

Gallagher · Controller 6000 Firmware

Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 6000 vCR8.60 versions prior to 220303a; vCR8.50 versions prior to 220303a; vCR8.40 versions prior to 220303a; vCR8.30 versions prior to 220303a.

7.5 CVSS 3.1 High EPSS 0.91% · top 41.3% CWE-754 · CWE-754
7.5CVSS 3.1 base score, v2 7.8
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP address. This issue affects: Gallagher Gallagher Controller 6000 vCR8.60 versions prior to 220303a; vCR8.50 versions prior to 220303a; vCR8.40 versions prior to 220303a; vCR8.30 versions prior to 220303a.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26078 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-24584Gallagher controller 6000 firmware classic buffer overflow vulnerabilityController 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: be…EPSS 0.50%8.8CVE-2023-24590Gallagher controller 6000 firmware vulnerabilityA format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash t…EPSS 0.61%4.6CVE-2023-41967Gallagher controller 6000 firmware vulnerabilitySensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Contro…EPSS 0.31%4.3CVE-2023-22439Gallagher controller 6000 firmware improper input validation vulnerabilityImproper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used …EPSS 0.51%9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 29%analysed8.8CVE-2023-41993Apple WebKit improper check allows arbitrary code executionCVE-2023-41993 is a WebKit flaw where processing web content can lead to arbitrary code execution, addressed with improved checks. Apple states it is…KEVEPSS 24%analysed7.8CVE-2023-41992Apple kernel privilege escalation via insufficient checksApple kernel code did not perform adequate checks, allowing a local attacker to elevate privileges. Apple states it is aware of a report that this is…KEVEPSS 9.5%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26078), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.