CVE-2020-5523

HIGH

Android App - SSL/TLS Man-In-The-Middle

Title source: llm
STIX 2.1

Description

Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

References (10)

Core 10
Core References
Third Party Advisory x_refsource_misc
http://www.dokodemobank.ne.jp/info_20200128_bankingapp.html
Third Party Advisory x_refsource_misc
https://www.ashikagabank.co.jp/appbanking/pdf/oshirase.pdf
Third Party Advisory x_refsource_misc
https://www.sihd-bk.jp/common_v2/pdf/20200127.pdf
Third Party Advisory x_refsource_misc
https://www.shikokubank.co.jp/info/apps20200128.html
Third Party Advisory x_refsource_misc
https://www.naganobank.co.jp/soshiki/2/app-ssl.html
Third Party Advisory x_refsource_misc
http://jvn.jp/en/jp/JVN28845872/index.html

Scores

CVSS v3 7.4
EPSS 0.0118
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (9)
77bank/77_bank < 2.0.1
ashikagabank/ashigin < 1.0.4
hokkaidobank/dogin < 3.0.1
hokugin/hokuriku_bank_portal < 2.0.1
naganobank/nagagin < 1.0.1
nttdata/mypallete
shikokubank/shikoku_bank < 2.0.1
sihd-bk/ikeda_senshu_bank < 3.0.4
tohoku-bank/tougin < 1.0.1
Published Jan 28, 2020
Tracked Since Feb 18, 2026