Описание
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.1 (включая)Версия до 1.0.4 (включая)Версия до 3.0.1 (включая)Версия до 2.0.1 (включая)Версия до 1.0.1 (включая)Версия до 2.0.1 (включая)Версия до 3.0.4 (включая)Версия до 1.0.1 (включая)
Одно из
cpe:2.3:a:77bank:77_bank:*:*:*:*:*:android:*:*
cpe:2.3:a:ashikagabank:ashigin:*:*:*:*:*:android:*:*
cpe:2.3:a:hokkaidobank:dogin:*:*:*:*:*:android:*:*
cpe:2.3:a:hokugin:hokuriku_bank_portal:*:*:*:*:*:android:*:*
cpe:2.3:a:naganobank:nagagin:*:*:*:*:*:android:*:*
cpe:2.3:a:nttdata:mypallete:-:*:*:*:*:android:*:*
cpe:2.3:a:shikokubank:shikoku_bank:*:*:*:*:*:android:*:*
cpe:2.3:a:sihd-bk:ikeda_senshu_bank:*:*:*:*:*:android:*:*
cpe:2.3:a:tohoku-bank:tougin:*:*:*:*:*:android:*:*
EPSS
Процентиль: 59%
0.00384
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-295
Связанные уязвимости
github
больше 3 лет назад
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
EPSS
Процентиль: 59%
0.00384
Низкий
7.4 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-295