Vulnerabilities (CVE)

Filtered by vendor Npci Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-9818 1 Npci 1 Bharat Interface For Money \(bhim\) 2024-02-28 5.0 MEDIUM 7.5 HIGH
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
CVE-2017-9821 1 Npci 1 Bharat Interface For Money \(bhim\) 2024-02-28 7.5 HIGH 9.8 CRITICAL
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.
CVE-2017-9819 1 Npci 1 Bharat Interface For Money \(bhim\) 2024-02-28 7.5 HIGH 9.8 CRITICAL
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.
CVE-2017-9820 1 Npci 1 Bharat Interface For Money \(bhim\) 2024-02-28 7.5 HIGH 9.8 CRITICAL
The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication.