QID 630792
QID 630792: For Android Vulnerability CVE-2021-23155
Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior versions.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-23155 to address this issue and obtain more information.
Vendor References
- CVE-2021-23155 -
nvd.nist.gov/vuln/detail/CVE-2021-23155
CVEs related to QID 630792
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-23155 | Android |
|