---
id: CVE-2025-47147
title: >-
  Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre
  Mobile Client on Android and iOS could allow an attacker with access to a
  logged-in Operator's mobile device to extract the session token and exploit
  access for a…
summary: >-
  Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre
  Mobile Client on Android and iOS could allow an attacker with access to a
  logged-in Operator's mobile device to extract the session token and exploit
  access for a…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-312
vendor: gallagher
product: command_centre_mobile
affected:
  - command_centre_mobile < 9.40.123
patched:
  - command_centre_mobile 9.40.123
published: '2026-03-03'
updated: '2026-08-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-47147'
references:
  - url: 'https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2025-47147'
    label: disclosures@gallagher.com
tags:
  - nvd
epss: 0.00071
epssPercentile: 0.00048
ingestedAt: '2026-08-14T19:20:02.814Z'
---

## Overview

Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. 

 

This issue affects Command Centre Mobile Client versions prior to 9.40.123.

## Affected

- `command_centre_mobile < 9.40.123`

## Remediation

Upgrade past the affected range:

- `command_centre_mobile 9.40.123`
