ZeroHour

CVE-2021-23162

CVSS 3.1
8.1 high
EPSS
<1%p34
Published
()
Modified
Description

Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.

Vendors
gallagher
Products
command centre mobile connect
Weakness
CWE-296, CWE-295
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.