CVE-2025-47147

Severity: Medium CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

Components affected: Command Centre Mobile Client for Android and iOS

Version of Mobile Client affected: Mobile Client versions prior to 9.40.123

Reported by: Gallagher Internal

Active exploitation of vulnerability*: No

Description of vulnerability: Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration.

*This indicates whether Gallagher are aware of this being actively exploited against customer sites at the time of publication.

Stay up to date with Gallagher

Get the latest Gallagher news, updates, and event information delivered straight to your inbox.