CVE-2025-47147
CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects Command Centre Mobile Client versions prior to 9.40.123.
| CWE | CWE-312 |
| Vendor | gallagher |
| Product | command centre mobile client |
| Published | Mar 3, 2026 |
| Last Updated | Mar 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for gallagher command centre mobile client
Be the first to know when new medium vulnerabilities affecting gallagher command centre mobile client are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Gallagher / Command Centre Mobile Client
9.40 < 9.40.123