{"api_version":"1","generated_at":"2026-07-23T13:19:55+00:00","cve":"CVE-2020-5523","urls":{"html":"https://cve.report/CVE-2020-5523","api":"https://cve.report/api/cve/CVE-2020-5523.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-5523","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-5523"},"summary":{"title":"CVE-2020-5523","description":"Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2020-01-28 06:15:00","updated_at":"2020-01-31 20:24:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://www.sihd-bk.jp/common_v2/pdf/20200127.pdf","name":"https://www.sihd-bk.jp/common_v2/pdf/20200127.pdf","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"404"},{"url":"https://www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf","name":"https://www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.dokodemobank.ne.jp/info_20200128_bankingapp.html","name":"http://www.dokodemobank.ne.jp/info_20200128_bankingapp.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"【どこでもバンク】 あなたの新しいネットバンキング | HOME","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.tohoku-bank.co.jp/news/topics/200128_applissl.html","name":"https://www.tohoku-bank.co.jp/news/topics/200128_applissl.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"とうぎんアプリにおけるSSL通信時の複数の脆弱性に関するお知らせ｜東北銀行","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf","name":"https://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN28845872/index.html","name":"http://jvn.jp/en/jp/JVN28845872/index.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"JVN#28845872: Android App \"MyPallete\" vulnerable to improper server certificate verification","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"https://www.naganobank.co.jp/soshiki/2/app-ssl.html","name":"https://www.naganobank.co.jp/soshiki/2/app-ssl.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"ながぎんアプリにおけるSSL通信時の複数の脆弱性に関するお知らせ - 長野銀行","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.hokugin.co.jp/info/archives/personal/2020/1913.html","name":"https://www.hokugin.co.jp/info/archives/personal/2020/1913.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"『北陸銀行ポータルアプリ』におけるSSL通信時の脆弱性の修正に関するお知らせ｜お知らせ｜北陸銀行","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf","name":"https://www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.shikokubank.co.jp/info/apps20200128.html","name":"https://www.shikokubank.co.jp/info/apps20200128.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"四国銀行アプリにおけるSSL通信時の複数の脆弱性に関するお知らせ | 四国銀行","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-5523","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5523","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"2.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"77bank","cpe5":"77_bank","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"1.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ashikagabank","cpe5":"ashigin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"3.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hokkaidobank","cpe5":"dogin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"2.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hokugin","cpe5":"hokuriku_bank_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"1.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"naganobank","cpe5":"nagagin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nttdata","cpe5":"mypallete","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nttdata","cpe5":"mypallete","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"2.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"shikokubank","cpe5":"shikoku_bank","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"3.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sihd-bk","cpe5":"ikeda_senshu_bank","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5523","vulnerable":"1","versionEndIncluding":"1.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tohoku-bank","cpe5":"tougin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","references":{"reference_data":[{"url":"http://www.dokodemobank.ne.jp/info_20200128_bankingapp.html","refsource":"MISC","name":"http://www.dokodemobank.ne.jp/info_20200128_bankingapp.html"},{"url":"https://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf","refsource":"MISC","name":"https://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf"},{"url":"https://www.sihd-bk.jp/common_v2/pdf/20200127.pdf","refsource":"MISC","name":"https://www.sihd-bk.jp/common_v2/pdf/20200127.pdf"},{"url":"https://www.shikokubank.co.jp/info/apps20200128.html","refsource":"MISC","name":"https://www.shikokubank.co.jp/info/apps20200128.html"},{"url":"https://www.tohoku-bank.co.jp/news/topics/200128_applissl.html","refsource":"MISC","name":"https://www.tohoku-bank.co.jp/news/topics/200128_applissl.html"},{"url":"https://www.naganobank.co.jp/soshiki/2/app-ssl.html","refsource":"MISC","name":"https://www.naganobank.co.jp/soshiki/2/app-ssl.html"},{"url":"https://www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf","refsource":"MISC","name":"https://www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf"},{"url":"https://www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf","refsource":"MISC","name":"https://www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf"},{"url":"https://www.hokugin.co.jp/info/archives/personal/2020/1913.html","refsource":"MISC","name":"https://www.hokugin.co.jp/info/archives/personal/2020/1913.html"},{"url":"http://jvn.jp/en/jp/JVN28845872/index.html","refsource":"MISC","name":"http://jvn.jp/en/jp/JVN28845872/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate."}]},"data_type":"CVE","affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"version":{"version_data":[{"version_value":"MyPallete all versions, AshikagaBankingAppli ver1.0.4 and earlier, SENSHUIKEDABANKBankingAppli ver3.0.4 and earlier, ShikokuBankingAppli ver2.0.1 and earlier, TohokuBankingAppli ver1.0.1 and earlier, NaganoBankingAppli ver1.0.1 and earlier, 77BankingAppli ver2.0.1 and earlier, HokkaidoBankingAppli ver3.0.1 and earlier, and HokurikuBankingAppli ver2.0.1 and earlier"}]},"product_name":"'MyPallete' and some of the Android banking applications that use 'MyPallete'"}]},"vendor_name":"NTT Data Corporation"}]}},"CVE_data_meta":{"ID":"CVE-2020-5523","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"data_format":"MITRE","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Fails to verify SSL certificates"}]}]}},"nvd":{"publishedDate":"2020-01-28 06:15:00","lastModifiedDate":"2020-01-31 20:24:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nttdata:mypallete:-:*:*:*:*:android:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ashikagabank:ashigin:*:*:*:*:*:android:*:*","versionEndIncluding":"1.0.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sihd-bk:ikeda_senshu_bank:*:*:*:*:*:android:*:*","versionEndIncluding":"3.0.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:shikokubank:shikoku_bank:*:*:*:*:*:android:*:*","versionEndIncluding":"2.0.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tohoku-bank:tougin:*:*:*:*:*:android:*:*","versionEndIncluding":"1.0.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:naganobank:nagagin:*:*:*:*:*:android:*:*","versionEndIncluding":"1.0.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:77bank:77_bank:*:*:*:*:*:android:*:*","versionEndIncluding":"2.0.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hokkaidobank:dogin:*:*:*:*:*:android:*:*","versionEndIncluding":"3.0.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:hokugin:hokuriku_bank_portal:*:*:*:*:*:android:*:*","versionEndIncluding":"2.0.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"5523","Ordinal":"165769","Title":"CVE-2020-5523","CVE":"CVE-2020-5523","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"5523","Ordinal":"1","NoteData":"Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"5523","Ordinal":"2","NoteData":"2020-01-28","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"5523","Ordinal":"3","NoteData":"2020-01-28","Type":"Other","Title":"Modified"}]}}}