{"id":"CVE-2025-47147","title":"Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a…","summary":"Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a…","severity":"medium","cvss":5.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-312"],"vendor":"gallagher","product":"command_centre_mobile","affected":["command_centre_mobile < 9.40.123"],"patched":["command_centre_mobile 9.40.123"],"published":"2026-03-03","updated":"2026-08-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-47147","references":[{"url":"https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-47147","label":"disclosures@gallagher.com"}],"tags":["nvd"],"epss":0.00071,"epssPercentile":0.00063,"ingestedAt":"2026-08-14T19:20:02.814Z","slug":"CVE-2025-47147","body":"## Overview\n\nCleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. \n\n \n\nThis issue affects Command Centre Mobile Client versions prior to 9.40.123.\n\n## Affected\n\n- `command_centre_mobile < 9.40.123`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `command_centre_mobile 9.40.123`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}