Sensitive Information Exposure in Gallagher Morpho Integration
CVE-2025-47699

9.9CRITICAL

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
23 October 2025

What is CVE-2025-47699?

The Gallagher Morpho integration is susceptible to information exposure that could allow an authenticated operator with limited permissions to make unauthorized modifications to local Morpho devices. This vulnerability raises concerns about the integrity and security of sensitive system data, potentially leading to significant operational risks.

Affected Version(s)

Command Centre Server 0 <= 8.90

Command Centre Server 9.30 < 9.30.2482 (MR2)

Command Centre Server 9.20 < 9.20.2819 (MR4)

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47699 : Sensitive Information Exposure in Gallagher Morpho Integration