Improper Validation Vulnerability in Gallagher Command Centre Mobile Client for Android
CVE-2021-23155
9CRITICAL
What is CVE-2021-23155?
The Gallagher Command Centre Mobile Client for Android suffers from an improper validation of the cloud certificate chain, which could allow attackers to perform man-in-the-middle attacks. This flaw enables malicious entities to impersonate legitimate servers, compromising the integrity of communication between the mobile client and the Command Centre Server. Versions affected include those prior to 8.60.065 and all prior 8.50 releases, putting sensitive data at risk due to this vulnerability.
Affected Version(s)
Command Centre Mobile Client for Android <= 8.50
Command Centre Mobile Client for Android 8.60 < 8.60.065
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
