The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References
Link | Resource |
---|---|
https://medium.com/@chronic_9612/follow-up-76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-64185035029f | Press/Media Coverage Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-05-05 00:29
Updated : 2017-05-17 04:27
NVD link : CVE-2017-5915
Mitre link : CVE-2017-5915
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
emirates_nbd_bank_p.j.s.c
- emirates_nbd
- emirates_nbd_ksa