CVE-2020-5523
3Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackepss 1.2%
probabilidade de exploração
1.2%top 34% das CVEs
exploração observada
nãonenhuma fonte reporta
Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Produtos afetados
NTT Data Corporation · 'MyPallete' and some of the Android banking applications that use 'MyPallete'Referências
http://jvn.jp/en/jp/JVN28845872/index.htmlhttps://www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdfhttps://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdfhttps://www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdfhttps://www.hokugin.co.jp/info/archives/personal/2020/1913.htmlhttps://www.naganobank.co.jp/soshiki/2/app-ssl.htmlhttps://www.shikokubank.co.jp/info/apps20200128.htmlhttps://www.sihd-bk.jp/common_v2/pdf/20200127.pdfhttps://www.tohoku-bank.co.jp/news/topics/200128_applissl.htmlhttp://www.dokodemobank.ne.jp/info_20200128_bankingapp.html