Cleartext Storage Vulnerability in Gallagher Command Centre Server
CVE-2025-48428

6.7MEDIUM

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
23 October 2025

What is CVE-2025-48428?

The vulnerability in Gallagher Command Centre Server stems from the cleartext storage of sensitive information, enabling an authenticated user to access and export critical signing keys. This flaw can be exploited to facilitate the deployment of compromised or counterfeit devices within the affected systems. Affected versions include Command Centre Server 9.20 before vEL9.20.2819, 9.10 before vEL9.10.3672, and all predecessors, emphasizing the necessity for upgrades to safeguard sensitive operational data.

Affected Version(s)

Command Centre Server 0 <= 8.90

Command Centre Server 9.20 < 9.20.2819 (MR4)

Command Centre Server 9.10 < 9.10.3672 (MR7)

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48428 : Cleartext Storage Vulnerability in Gallagher Command Centre Server