CVE-2016-4818
MEDIUMDmmfx Demo Trade < 1.5.0 - Improper Certificate Validation
Title source: ruleDescription
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.
References (5)
Scores
CVSS v3
5.9
EPSS
0.0056
EPSS Percentile
68.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-295
Status
published
Affected Products (4)
dmm/dmmfx_demo_trade
< 1.5.0
dmm/dmmfx_trade
< 1.5.0
dmm/gaitamejapan_fx_trade
< 1.4.0
n/a/n/a
Timeline
Published
Apr 20, 2017
Tracked Since
Feb 18, 2026