Exposure of Personal Data in Command Centre Server by Gallagher
CVE-2025-35981

5.5MEDIUM

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
23 October 2025

What is CVE-2025-35981?

A security flaw in Gallagher's Command Centre Server allows privileged operators to access personal information about cardholders that they should not be able to view. This vulnerability presents a risk of unauthorized disclosure of sensitive data, compromising user privacy and potentially leading to further security concerns. It impacts specific versions of the software, necessitating prompt attention and remediation.

Affected Version(s)

Command Centre Server 9.30.1874 (MR1)

Command Centre Server 9.20.2337 (MR3)

Command Centre Server 9.10.3194 (MR6)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-35981 : Exposure of Personal Data in Command Centre Server by Gallagher