PT-2021-15396 · Gallagher · Gallagher Command Centre Mobile Connect

Published

2021-11-18

·

Updated

2021-11-23

·

CVE-2021-23162

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gallagher Command Centre Mobile Connect for Android versions prior to 15.04.040 Gallagher Command Centre Mobile Connect for Android version 14 and prior versions
Description The issue is related to improper validation of the cloud certificate chain in Mobile Connect, which allows a man-in-the-middle attack to impersonate the legitimate Command Centre Server.
Recommendations For versions prior to 15.04.040, update to version 15.04.040 or later to resolve the issue. For version 14 and prior versions, update to a version later than 14 to mitigate the risk.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23162

Affected Products

Gallagher Command Centre Mobile Connect