CVE Vulnerabilities

CVE-2016-4818

Improper Certificate Validation

Published: Apr 20, 2017 | Modified: Apr 26, 2017
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Dmmfx_demo_trade Dmm * 1.5.0 (including)
Dmmfx_trade Dmm * 1.5.0 (including)
Gaitamejapan_fx_trade Dmm * 1.4.0 (including)

Potential Mitigations

References