← Vulnerability feed

Vulnerability record · CVE-2023-22439 · published 18 December 2023

CVE-2023-22439: Gallagher controller 6000 firmware improper input validation vulnerability

Gallagher · Controller 6000 Firmware

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

4.3 CVSS 3.1 Medium EPSS 0.51% · top 58.4% CWE-20 · Improper input validation
4.3CVSS 3.1 base score
0.51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22439 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-24584Gallagher controller 6000 firmware classic buffer overflow vulnerabilityController 6000 is vulnerable to a buffer overflow via the Controller diagnostic web interface upload feature. This issue affects Controller 6000: be…EPSS 0.50%9.8CVE-2020-16098Gallagher command centre improper authentication vulnerabilityIt is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior…EPSS 1.1%9.8CVE-2019-15294Gallagher command centre sensitive information in log file vulnerabilityAn issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visito…EPSS 1.2%8.8CVE-2023-24590Gallagher controller 6000 firmware vulnerabilityA format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash t…EPSS 0.61%8.8CVE-2021-23140Gallagher command centre improper authorization vulnerabilityImproper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre O…EPSS 0.85%8.8CVE-2020-16103Gallagher command centre type confusion vulnerabilityType confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue af…EPSS 2.3%8.6CVE-2026-25193Gallagher active directory sync sensitive information in log file vulnerabilityInsertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposu…EPSS 0.14%8.2CVE-2020-16102Gallagher command centre improper authentication vulnerabilityImproper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid confi…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2023-22439), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.