First published: Thu Nov 18 2021(Updated: )
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior versions.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre Mobile Connect | <=8.50 | |
Gallagher Command Centre Mobile Connect | >=8.60<8.60.065 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-23155 is considered high due to its potential to allow man-in-the-middle attacks.
To fix CVE-2021-23155, upgrade the Gallagher Command Centre Mobile Client for Android to version 8.60.065 or higher.
CVE-2021-23155 affects Gallagher Command Centre Mobile Client for Android versions 8.50 and earlier, as well as versions 8.60 below 8.60.065.
If you are using Gallagher Command Centre Mobile Client for Android prior to version 8.60.065 or version 8.50 or lower, your device is vulnerable to CVE-2021-23155.
CVE-2021-23155 enables a man-in-the-middle attack, allowing an unauthorized party to impersonate the legitimate Command Centre Server.