CVE Vulnerabilities

CVE-2020-5523

Improper Certificate Validation

Published: Jan 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Android App MyPallete and some of the Android banking applications based on MyPallete do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
77_bank77bank*2.0.1 (including)
AshiginAshikagabank*1.0.4 (including)
DoginHokkaidobank*3.0.1 (including)
Hokuriku_bank_portalHokugin*2.0.1 (including)
NagaginNaganobank*1.0.1 (including)
MypalleteNttdata- (including)- (including)
Shikoku_bankShikokubank*2.0.1 (including)
Ikeda_senshu_bankSihd-bk*3.0.4 (including)
TouginTohoku-bank*1.0.1 (including)

Potential Mitigations

References