๐Ÿ” CVE Alert

CVE-2025-47147

MEDIUM 5.7
CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects Command Centre Mobile Client versions prior to 9.40.123.

CWE CWE-312
Vendor gallagher
Product command centre mobile client
Published Mar 3, 2026
Last Updated Mar 3, 2026
Stay Ahead of the Next One

Get instant alerts for gallagher command centre mobile client

Be the first to know when new medium vulnerabilities affecting gallagher command centre mobile client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Gallagher / Command Centre Mobile Client
9.40 < 9.40.123

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.gallagher.com: https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-47147