Improper Following of a Certificate's Chain of Trust
CVE-2021-23162
Summary
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.
- HIGH
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-296 - Improper Following of a Certificate's Chain of Trust
The software does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any resource that is associated with that certificate.
References
Advisory Timeline
- Published