Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Project Subscriptions
| Vendors | Products |
|---|---|
|
77bank
Subscribe
|
77 Bank
Subscribe
|
|
Ashikagabank
Subscribe
|
Ashigin
Subscribe
|
|
Hokkaidobank
Subscribe
|
Dogin
Subscribe
|
|
Hokugin
Subscribe
|
Hokuriku Bank Portal
Subscribe
|
|
Naganobank
Subscribe
|
Nagagin
Subscribe
|
|
Nttdata
Subscribe
|
Mypallete
Subscribe
|
|
Shikokubank
Subscribe
|
Shikoku Bank
Subscribe
|
|
Sihd-bk
Subscribe
|
Ikeda Senshu Bank
Subscribe
|
|
Tohoku-bank
Subscribe
|
Tougin
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26686 | Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-04T08:30:24.582Z
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5523
No data.
Status : Modified
Published: 2020-01-28T06:15:12.353
Modified: 2024-11-21T05:34:12.540
Link: CVE-2020-5523
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD