CVE-2025-44003 Details
Description
Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a limited denial of service when 125 kHz Card Technology is enabled. This issue affects T-Series Readers: 9.20 prior to vCR9.20.250213a (distributed in 9.20.1827 (MR2)), 9.10 prior to vCR9.10.250213a (distributed in 9.10.2692(MR5)), 9.00 prior to vCR9.00.250619a (distributed in vEL9.00.3371 (MR7)), all versions of 8.90 and prior.
A resource management vulnerability has been identified in Gallagher T-Series Readers, specifically in versions 9.20 prior to vCR9.20.250213a, 9.10 prior to vCR9.10.250213a, 9.00 prior to vCR9.00.250619a, and all versions of 8.90 and prior. This vulnerability, categorized as Missing Release of Resource after Effective Lifetime (CWE-772), allows an attacker with physical access to the reader to cause a limited denial-of-service, but only when 125 kHz Card Technology is enabled.
Disabling 125 kHz Card Technology on the affected reader prevents exploitation of this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2025CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-44003 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-772 | Missing Release of Resource after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Gallagher T-Series Reader | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | New CVE Received | [email protected] |
Volerion