CVE-2025-44003

MEDIUM

Gallagher T-Series Reader <9.20.250213a, <9.10.2692(MR5), <9.00.337...

Title source: llm
STIX 2.1

Description

Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a limited denial of service when 125 kHz Card Technology is enabled. This issue affects T-Series Readers: 9.20 prior to vCR9.20.250213a (distributed in 9.20.1827 (MR2)), 9.10 prior to vCR9.10.250213a (distributed in 9.10.2692(MR5)), 9.00 prior to vCR9.00.250619a (distributed in  vEL9.00.3371 (MR7)),  all versions of 8.90 and prior.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-772
Status published
Products (4)
Gallagher/T-Series Readers < 8.90
Gallagher/T-Series Readers 9.00 - vCR9.00.250619a
Gallagher/T-Series Readers 9.10 - vCR9.10.250213a
Gallagher/T-Series Readers 9.20 - vCR9.20.250213a
Published Jul 10, 2025
Tracked Since Feb 18, 2026