CVE-2017-9820

CRITICAL

BHIM 1.3 - Improper Authentication via Accessibility Service

Title source: llm
STIX 2.1

Description

The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication.

Scores

CVSS v3 9.8
EPSS 0.0183
EPSS Percentile 76.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
npci/bharat_interface_for_money_\(bhim\) 1.3
Published Aug 24, 2018
Tracked Since Feb 18, 2026