The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://medium.com/%40chronic_9612/follow-up-76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-64185035029f - |
07 Nov 2023, 02:49
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2017-05-05 07:29
Updated : 2024-11-21 03:28
NVD link : CVE-2017-5915
Mitre link : CVE-2017-5915
CVE.ORG link : CVE-2017-5915
JSON object : View
Products Affected
emirates_nbd_bank_p.j.s.c
- emirates_nbd
- emirates_nbd_ksa
CWE
CWE-295
Improper Certificate Validation