CVE-2020-5523
Summary
| CVE | CVE-2020-5523 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-28 06:15:00 UTC |
| Updated | 2020-01-31 20:24:00 UTC |
| Description | Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | 77bank | 77 Bank | All | All | All | All |
| Application | Ashikagabank | Ashigin | All | All | All | All |
| Application | Hokkaidobank | Dogin | All | All | All | All |
| Application | Hokugin | Hokuriku Bank Portal | All | All | All | All |
| Application | Naganobank | Nagagin | All | All | All | All |
| Application | Nttdata | Mypallete | - | All | All | All |
| Application | Nttdata | Mypallete | - | All | All | All |
| Application | Shikokubank | Shikoku Bank | All | All | All | All |
| Application | Sihd-bk | Ikeda Senshu Bank | All | All | All | All |
| Application | Tohoku-bank | Tougin | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.sihd-bk.jp/common_v2/pdf/20200127.pdf | MISC | www.sihd-bk.jp | Third Party Advisory |
| www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf | MISC | www.77bank.co.jp | Third Party Advisory |
| 【どこでもバンク】 あなたの新しいネットバンキング | HOME | MISC | www.dokodemobank.ne.jp | Third Party Advisory |
| とうぎんアプリにおけるSSL通信時の複数の脆弱性に関するお知らせ|東北銀行 | MISC | www.tohoku-bank.co.jp | Third Party Advisory |
| www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf | MISC | www.ashikagabank.co.jp | Third Party Advisory |
| JVN#28845872: Android App "MyPallete" vulnerable to improper server certificate verification | MISC | jvn.jp | Third Party Advisory |
| ながぎんアプリにおけるSSL通信時の複数の脆弱性に関するお知らせ - 長野銀行 | MISC | www.naganobank.co.jp | Third Party Advisory |
| 『北陸銀行ポータルアプリ』におけるSSL通信時の脆弱性の修正に関するお知らせ|お知らせ|北陸銀行 | MISC | www.hokugin.co.jp | Third Party Advisory |
| www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf | MISC | www.hokkaidobank.co.jp | Third Party Advisory |
| 四国銀行アプリにおけるSSL通信時の複数の脆弱性に関するお知らせ | 四国銀行 | MISC | www.shikokubank.co.jp | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.