Medium severity5.7NVD Advisory· Published Mar 3, 2026· Updated Aug 14, 2026
CVE-2025-47147
CVE-2025-47147
Description
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration.
This issue affects Command Centre Mobile Client versions prior to 9.40.123.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
49.40+ 1 more
- (no CPE)range: 9.40
- (no CPE)range: <9.40.123
cpe:2.3:a:gallagher:command_centre_mobile:*:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:gallagher:command_centre_mobile:*:*:*:*:*:android:*:*range: <9.40.123
- cpe:2.3:a:gallagher:command_centre_mobile:*:*:*:*:*:iphone_os:*:*range: <9.40.123
Patches
Vulnerability mechanics
References
1- security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-47147nvdVendor Advisory
News mentions
0No linked articles in our index yet.