Executive brief
Gallagher's video management system integrations for NxWitness and Hanwha cameras transmit sensitive stream data without encryption. An attacker with access to the local network can view live video feeds without authentication, potentially exposing surveillance of facilities, employees, or restricted areas.
Technical details
The vulnerability is a cleartext transmission issue (CWE-319) in a component used by Gallagher NxWitness VMS and Hanwha VMS integrations with Command Centre. Unprivileged users with network access can intercept and view live video streams because the integration does not encrypt transmitted video data. No authentication is required to exploit this issue; an attacker simply needs local network access to the integration component. The fix is available in NxWitness VMS integration version 9.10.017 and later, and Hanwha VMS integration version 9.10.025 and later.
Affected products
- Gallagher NxWitness VMS integration prior to 9.10.017
- Gallagher Hanwha VMS integration prior to 9.10.025
Timeline
- 2026-03-03: disclosed