Exposure of Personal Data in Command Centre Server by Gallagher
CVE-2025-35981
5.5MEDIUM
What is CVE-2025-35981?
A security flaw in Gallagher's Command Centre Server allows privileged operators to access personal information about cardholders that they should not be able to view. This vulnerability presents a risk of unauthorized disclosure of sensitive data, compromising user privacy and potentially leading to further security concerns. It impacts specific versions of the software, necessitating prompt attention and remediation.
Affected Version(s)
Command Centre Server 9.30.1874 (MR1)
Command Centre Server 9.20.2337 (MR3)
Command Centre Server 9.10.3194 (MR6)
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
