CVE-2016-4818

MEDIUM

Dmmfx Demo Trade < 1.5.0 - Improper Certificate Validation

Title source: rule

Description

DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.

Scores

CVSS v3 5.9
EPSS 0.0056
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-295
Status published

Affected Products (4)

dmm/dmmfx_demo_trade < 1.5.0
dmm/dmmfx_trade < 1.5.0
dmm/gaitamejapan_fx_trade < 1.4.0
n/a/n/a

Timeline

Published Apr 20, 2017
Tracked Since Feb 18, 2026