Lucene search

K
cveMitreCVE-2017-5911
HistoryMay 05, 2017 - 7:29 a.m.

CVE-2017-5911

2017-05-0507:29:00
CWE-295
mitre
web.nvd.nist.gov
27
banco santander
mexico
supermovil app
ios
ssl
certificate
security
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

33.2%

The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected configurations

Nvd
Node
banco_santander_mexico_sasupermovilMatch3.5iphone_os
OR
banco_santander_mexico_sasupermovilMatch3.6iphone_os
OR
banco_santander_mexico_sasupermovilMatch3.7iphone_os
VendorProductVersionCPE
banco_santander_mexico_sasupermovil3.5cpe:2.3:a:banco_santander_mexico_sa:supermovil:3.5:*:*:*:*:iphone_os:*:*
banco_santander_mexico_sasupermovil3.6cpe:2.3:a:banco_santander_mexico_sa:supermovil:3.6:*:*:*:*:iphone_os:*:*
banco_santander_mexico_sasupermovil3.7cpe:2.3:a:banco_santander_mexico_sa:supermovil:3.7:*:*:*:*:iphone_os:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

33.2%

Related for CVE-2017-5911