QID 630791
QID 630791: For Android Vulnerability CVE-2021-23162
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-23162 to address this issue and obtain more information.
Vendor References
- CVE-2021-23162 -
nvd.nist.gov/vuln/detail/CVE-2021-23162
CVEs related to QID 630791
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-23162 | Android |
|