« Volver al listado

CVE-2025-47147

Estado: AnalizadaMedia (5.7)—

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration.

This issue affects Command Centre Mobile Client versions prior to 9.40.123.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-47147",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-47147",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-03T15:44:10.549714Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosures@gallagher.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "disclosures@gallagher.com",
      "affectedData": [
        {
          "vendor": "Gallagher",
          "product": "Command Centre Mobile Client",
          "versions": [
            {
              "status": "affected",
              "version": "9.40",
              "lessThan": "9.40.123",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Android",
            "iOS"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-03-03T03:15:54.190",
  "references": [
    {
      "url": "https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-47147",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosures@gallagher.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosures@gallagher.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-312"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. \n\n \n\nThis issue affects Command Centre Mobile Client versions prior to 9.40.123."
    },
    {
      "lang": "es",
      "value": "Almacenamiento en texto claro de información sensible (CWE-312) en el Cliente móvil de Command Centre en Android e iOS podría permitir a un atacante con acceso al dispositivo móvil de un operador con sesión iniciada extraer el token de sesión y explotar el acceso por una duración limitada.\n\nEste problema afecta a las versiones del Cliente móvil de Command Centre anteriores a la 9.40.123."
    }
  ],
  "lastModified": "2026-08-14T18:51:26.530",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre_mobile:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A220463-8AFB-4832-AAC0-04325423686C",
              "versionEndExcluding": "9.40.123"
            },
            {
              "criteria": "cpe:2.3:a:gallagher:command_centre_mobile:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A191C48-21BC-4FF5-8772-09473F962F32",
              "versionEndExcluding": "9.40.123"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosures@gallagher.com"
}