Improper Validation Vulnerability in Gallagher Command Centre Mobile Client for Android
CVE-2021-23155

9CRITICAL

Key Information:

Vendor

Gallagher

Vendor
CVE Published:
18 November 2021

What is CVE-2021-23155?

The Gallagher Command Centre Mobile Client for Android suffers from an improper validation of the cloud certificate chain, which could allow attackers to perform man-in-the-middle attacks. This flaw enables malicious entities to impersonate legitimate servers, compromising the integrity of communication between the mobile client and the Command Centre Server. Versions affected include those prior to 8.60.065 and all prior 8.50 releases, putting sensitive data at risk due to this vulnerability.

Affected Version(s)

Command Centre Mobile Client for Android <= 8.50

Command Centre Mobile Client for Android 8.60 < 8.60.065

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.