CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
58.7%
Android App ‘MyPallete’ and some of the Android banking applications based on ‘MyPallete’ do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Vendor | Product | Version | CPE |
---|---|---|---|
77bank | 77_bank | * | cpe:2.3:a:77bank:77_bank:*:*:*:*:*:android:*:* |
ashikagabank | ashigin | * | cpe:2.3:a:ashikagabank:ashigin:*:*:*:*:*:android:*:* |
hokkaidobank | dogin | * | cpe:2.3:a:hokkaidobank:dogin:*:*:*:*:*:android:*:* |
hokugin | hokuriku_bank_portal | * | cpe:2.3:a:hokugin:hokuriku_bank_portal:*:*:*:*:*:android:*:* |
naganobank | nagagin | * | cpe:2.3:a:naganobank:nagagin:*:*:*:*:*:android:*:* |
nttdata | mypallete | - | cpe:2.3:a:nttdata:mypallete:-:*:*:*:*:android:*:* |
shikokubank | shikoku_bank | * | cpe:2.3:a:shikokubank:shikoku_bank:*:*:*:*:*:android:*:* |
sihd-bk | ikeda_senshu_bank | * | cpe:2.3:a:sihd-bk:ikeda_senshu_bank:*:*:*:*:*:android:*:* |
tohoku-bank | tougin | * | cpe:2.3:a:tohoku-bank:tougin:*:*:*:*:*:android:*:* |
[
{
"product": "'MyPallete' and some of the Android banking applications that use 'MyPallete'",
"vendor": "NTT Data Corporation",
"versions": [
{
"status": "affected",
"version": "MyPallete all versions, AshikagaBankingAppli ver1.0.4 and earlier, SENSHUIKEDABANKBankingAppli ver3.0.4 and earlier, ShikokuBankingAppli ver2.0.1 and earlier, TohokuBankingAppli ver1.0.1 and earlier, NaganoBankingAppli ver1.0.1 and earlier, 77BankingAppli ver2.0.1 and earlier, HokkaidoBankingAppli ver3.0.1 and earlier, and HokurikuBankingAppli ver2.0.1 and earlier"
}
]
}
]
jvn.jp/en/jp/JVN28845872/index.html
www.dokodemobank.ne.jp/info_20200128_bankingapp.html
www.77bank.co.jp/pdf/oshirase/20012801_appvulnerability.pdf
www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf
www.hokkaidobank.co.jp/common/dat/2020/0120/15795047141946146699.pdf
www.hokugin.co.jp/info/archives/personal/2020/1913.html
www.naganobank.co.jp/soshiki/2/app-ssl.html
www.shikokubank.co.jp/info/apps20200128.html
www.sihd-bk.jp/common_v2/pdf/20200127.pdf
www.tohoku-bank.co.jp/news/topics/200128_applissl.html
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
58.7%