First published: Thu Nov 18 2021(Updated: )
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre Mobile Connect | <=14.0 | |
Gallagher Command Centre Mobile Connect | >=15.0<15.04.040 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23162 is a vulnerability that allows a man-in-the-middle attack to impersonate the legitimate Command Centre Server in Mobile Connect for Android.
CVE-2021-23162 has a severity rating of 8.1 (high).
Gallagher Command Centre Mobile Connect for Android versions 14.0 prior to 15.04.040 are affected.
To prevent a man-in-the-middle attack in Mobile Connect for Android, it is recommended to update to version 15.04.040 or later.
More information about CVE-2021-23162 can be found at the following link: [Gallagher Security Advisory](https://security.gallagher.com/Security-Advisories/CVE-2021-23162)