PT-2021-15395 · Gallagher · Gallagher Command Centre Mobile Client

Published

2021-11-18

·

Updated

2021-11-23

·

CVE-2021-23155

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gallagher Command Centre Mobile Client for Android versions prior to 8.60.065 Gallagher Command Centre Mobile Client for Android version 8.50 and prior versions
Description The issue is related to improper validation of the cloud certificate chain in the Mobile Client, allowing a man-in-the-middle attack to impersonate the legitimate Command Centre Server.
Recommendations For versions prior to 8.60.065, update to version 8.60.065 or later to resolve the issue. For version 8.50 and prior versions, update to a version later than 8.50 to resolve the issue.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23155

Affected Products

Gallagher Command Centre Mobile Client